Getting Started
Audit Log
Owner and manager investigation log for important changes, payments, shared devices, and AI decisions.
Last updated 14 July 2026
Audit Log is the owner and manager record of important venue changes. Use it when you need to investigate what happened, who acted, when it happened, and which booking, order, client, shared device, or AI action was involved.
Find it on web at Settings > Security > Audit Log.
TL;DR
- Audit Log records important venue changes for owner and manager investigation.
- Use Activity Feed for work that needs attention now; use Audit Log when you need accountability history.
- Owners can copy summaries and export CSV files. Managers can view the log but cannot export.
- Audit Log redacts unsafe prompts, secrets, full card data, and private raw payloads.
Audit Log vs Activity Feed
| Surface | Use it for | Who sees it |
|---|---|---|
| Activity Feed | Notifications, unread items, and work that needs attention now. | Staff see targeted items. Owners and managers see venue-wide activity. |
| Audit Log | Investigation and accountability for important changes and decisions. | Owners and managers only. |
Audit Log is not another notification feed. It does not replace unread counts, push notifications, or action prompts.
What's included
Audit Log includes high-risk write and lifecycle events such as:
- Checkout completion and payment-attempt history.
- Booking history from existing booking audit records.
- Shared-workstation approval, connection, rename, operator claim, lock, PIN failure, disconnect, booking, waitlist, time-clock, checkout and payment events where available.
- AI booking-concierge settings, approvals, rejects, blocked actions, executed actions, and thread pause/resume controls.
- Selected legacy AI and conversation lifecycle rows where the source has safe venue-scoped audit data.
Each row shows the time, actor, source, category, action, object, and summary. AI rows include lifecycle, execution mode, trace/cost references where available, risk tier, and confidence.
For a workstation-focused view, Owners and Managers can choose View device activity from Settings > Shared workstations. This opens Settings > Audit log with Workstation activity applied; the scope can be removed to return to the venue-wide investigation trail. Owner-only copy and CSV permissions remain unchanged.
Details and redaction
Open a row to see the detail drawer. The drawer may show before/after snapshots, linked records, customer-facing AI output, request metadata, and redaction notes.
Audit Log does not expose hidden prompts, system prompts, model reasoning, provider request bodies, secrets, full payment card data, or raw private payloads that are not safe for owner-facing review.
Export and copy
Owners can copy a text summary or export CSV from the Audit Log. Managers can view and filter the log but cannot copy the owner summary or export CSV.
CSV exports are designed for investigation handoff. They include list-level fields and AI lifecycle metadata, but not raw JSON payloads.
The Audit Log opens on the last 14 days by default to keep investigations fast and infrastructure usage predictable. Use 30-day or 90-day ranges only when the investigation needs older events. Copy summaries are capped to the first 100 matching events and CSV exports are capped to the first 500 matching events.
Group admin note
The venue Audit Log remains venue-scoped. Multi-location groups with group admin access can also use All locations -> Audit for the separate group-level audit stream.
FAQ
Where is the Audit Log?
Audit Log is on web at Settings > Security > Audit Log. Owners and managers can open the global Audit Log; staff cannot open it.
How is Audit Log different from Activity Feed?
Activity Feed shows notifications and work that needs attention. Audit Log records important changes and decisions for investigation.
Who can export audit data?
Owners can copy a summary or export CSV from Audit Log. Managers can view the global Audit Log but cannot export or copy the owner summary.