Audit (admins)
Every event the system records, across every case, plus administrative actions — newest first, append-only. Nothing here can be edited or removed.
What a row says
- When — in your time zone.
- Object — the case, or for admin events the user, entity, token or broadcast it happened to.
- Event — the same vocabulary as a case's timeline:
status change,response sent,timer started… and admin events such asrole changed,token revoked,entity created. - Actor — the person; system for what mail providers, webhooks and jobs did; Claude with an agent mark when an AI acted through someone's token — the token's owner is in the details.
- Channel — web, MCP (a token), email, SMS, or a scheduled job.
Click a row's event or details to open the event sheet: the same reading the case timeline gives, then every field the event recorded, as written. The table stays usable underneath; Esc closes it.
Filtering and export
Search a case ref, a name or free text; narrow by event, actor, the case's entity, channel and dates. Export (CSV, XLSX or JSON, with a time zone and row count) takes the events matching the filter.
Archived cases
Archiving redacts free text inside a case's events — notes, reasons — and leaves the events themselves. Reading an archived case's export is itself an event: archive export accessed.