System Logs & Audit Trail

Flowtly Editorial Team1 min

Flowtly maintains a system log and audit trail that records key actions taken across your organisation's projects, clients, people, and resourcing data. This record helps administrators and managers understand who performed an action, what was changed, and when it occurred, supporting accountability and compliance across the workspace.

What Is Recorded

The audit trail captures activity such as changes to organisation settings, updates to client and project records, adjustments to people and resourcing data, and other significant actions performed by users within the workspace. Each entry typically includes the user responsible for the action, the type of action taken, and the time it occurred.

Viewing the Audit Trail

Authorised users can review the audit trail to trace the history of changes within a given area, such as an organisation, project, or client record. This allows teams to confirm that data was updated correctly, investigate unexpected changes, and maintain a clear record of activity over time.

Access and Permissions

Access to system logs and audit trail information is controlled by role permissions, and viewing the audit trail requires an audit or management role. Organisation administrators see records across the organisation. Managers see the records their role is responsible for, so a project manager and a people manager each see the activity that belongs to their own area rather than the whole organisation.

Team members who hold neither an audit nor a management role do not have access to the audit trail, and the audit log page is unavailable to them. Audit entries name the person who performed each action, so access is kept to the roles that need it for accountability and compliance. If you need to review activity for an area you are responsible for, ask an organisation administrator which role covers it.

Example use cases

  • An organisation administrator reviews the audit trail to confirm which user updated a client's billing details.
  • A project manager checks the log history for a project to understand when a status change was made and by whom.
  • A resourcing lead investigates the audit trail after noticing an unexpected change to a team member's allocation.
  • A compliance reviewer examines activity across people records to verify that data handling followed organisation policy.
  • An invoices manager checks who moved an invoice line to a different project, and when, after a project's income changed unexpectedly.

Connection map

Refers toPart ofFulfils
Documented hereDocumented elsewhere
audit-log records person. setting defines attribute. org-document access governed by setting. subscription gates setting. setting requires second-factor. second-factor held by person. recovery-code stands in for second-factor. trusted-device waives second-factor.recordsdefinesaccess governed bygatesrequiresheld bystands in forwaivesAAudit trail — The record of who did what and when. It is how a user action is investigated after the fact, and what compliance is demonstrated from.Audit trailPPerson — An employee. The central record the rest of the workforce data hangs off — profile, documents, leave, benefits, rates.PersonSSetting — Platform-wide configuration — behaviours, permissions, security.SettingAAttribute — A custom data field defined once and collected across the platform, so an organisation can record what Flowtly does not ship a field for.AttributeDDocument — An organisational file, stored with control over who can reach it.DocumentSSubscription — The plan the organisation is on, and what it is billed for.SubscriptionSSecond factor — The extra proof of identity asked for at sign-in on top of the password — a six-digit code from an authenticator app, changing every 30 seconds.Second factorRRecovery code — One of ten single-use codes issued when an authenticator is confirmed. Each stands in for a code from the app once, for the day the phone is gone.Recovery codeTTrusted device — A browser a person has chosen to trust, which is not asked for a second factor again for 30 days. Per browser, not per person.Trusted device

Related terms