Audit Log Actions
Last updated: September 1, 2026
The audit log records key actions taken in your Ivo workspace so admins can review who did what, and when. This reference explains each action type that may appear in the log, grouped by category. The audit log is available to workspace admins under Settings.
Authentication & Security
Sign-in activity and security-related events.
Action | What it means |
|---|---|
| Someone signed in (or was blocked from signing in) |
| Someone signed out |
| Someone requested a password reset email |
| Someone completed a password reset |
| Someone turned on two-factor authentication |
| Someone completed a two-factor challenge |
| Someone turned off two-factor authentication |
| Someone was blocked from accessing something |
| Account locked out (too many failed attempts) |
| The list of allowed IP addresses was changed |
User & Workspace Management
Changes to workspace membership, roles, settings, and SSO.
Action | What it means |
|---|---|
| New members were added to the workspace |
| A member was removed from the workspace |
| A member's role or permissions were changed |
| Workspace settings were changed (e.g. name, support access) |
| SSO (single sign-on) was set up |
| SSO settings were changed |
| A service account was created |
| A service account was deleted |
| A service account was updated |
Contracts / Repository
Changes to contracts stored in your Rooms.
Action | What it means |
|---|---|
Delete contracts | Contracts were deleted from a Room |
Move contracts | Contracts were moved between Rooms |
Playbooks
Creation, edits, and access events for playbooks and their contents.
Action | What it means |
|---|---|
| A playbook was created |
| A playbook was edited or saved |
| A playbook was deleted |
| A playbook was imported (e.g. from Excel) |
| A playbook was exported |
| A playbook was opened or viewed |
| A checklist item was added to a playbook |
| A checklist item was edited |
| A checklist item was removed |
| A checklist item was viewed |
| A clause was added to a playbook |
| A clause was edited |
| A clause was removed from a playbook |
| A clause was viewed |
Teams
Changes to teams in the workspace.
Action | What it means |
|---|---|
| A team was deleted |
API Keys
Creation and deletion of API keys.
Action | What it means |
|---|---|
| An Ivo Connect API key was created |
| An Ivo Connect API key was deleted |
| A personal API key was created |
| A personal API key was deleted |
Integrations
Connection and sync events for Salesforce and Google Drive.
Action | What it means |
|---|---|
| Salesforce was connected |
| Salesforce was disconnected |
| A Salesforce sync was set up |
| A Salesforce sync was removed |
| A Salesforce import was started |
| Google Drive was connected |
| Google Drive was disconnected |
| A Google Drive sync was set up |
| A Google Drive sync was removed |
| A Google Drive import was started |
Webhooks
Webhook test events.
Action | What it means |
|---|---|
| A test webhook was sent |