← Help

Product help

Review business history and your account activity

Product team · Reviewed

Business history and your own account activity

Open Settings → Business audit history as a current workspace owner or administrator. Choose Business events, CRM changes and recovery, or Signature lifecycle. Each tab shows retained event metadata, its recorded actor when available, the source record and any retained revision or fingerprint. Follow the source link to inspect the authoritative record under its current permissions.

For example, choose CRM history and filter the event name by restored to find a client's recorded recovery. Use its exact source record ID to follow that client's retained changes. In Signature lifecycle, compare the retained document fingerprint with the agreement's existing verification view. An audit entry does not replace financial reconciliation or signature verification.

Filters and coverage

Filter an event name, exact record ID and inclusive UTC dates. Earlier entries uses a cursor bound to the selected workspace and filters. Refresh from newest to include later or delayed events. Events are bounded to the capture time shown on the page; this is a paginated operational view, not an exported database snapshot.

Business events use an explicit list of permitted business record types. Personal notes, assistant work, private account preferences, personal keepsake purchases and face-search activity are excluded. The desk never returns raw event payloads, message bodies, historical field values, signer IP addresses or device evidence. Business owners cannot use this view to inspect another person's account activity.

Named actors appear only when their retained reference resolves within the business. Former members are labeled. Events without a retained actor or a resolvable membership say so; an unknown actor is never inferred from the current record owner. Some old or provider-generated events lack named actors, and some actions predate event capture. An empty result does not prove that no action occurred.

Account activity stays with its account

Choose Your private account activity on Workspaces or Your account activity in Settings. Native settings also offers an online account-activity view. Only the signed-in person's retained, signature-verified Clerk session events appear, across that person's workspace memberships. An owner, administrator or API credential cannot select somebody else's identity.

Session-created, ended, removed and revoked events have occurrence and capture times and a one-way session reference. No raw session credential, IP address, location or device is returned. Provider session creation may accompany sign-in or another provider session; it is not proof of a specific person or device. Live capture requires identity-webhook activation, and historical sign-ins are not reconstructed. This view does not revoke sessions.

Native activity is fetched online and is not placed in the offline runbook. Leaving the foreground clears the displayed history. Physical-device behavior and real provider callbacks remain part of coordinated activation testing.

Recovery and retention

Use the existing CRM archive and recovery controls to restore eligible records; the history desk itself is read-only. Use private exports for retained records available to your authority. Log coverage, production retention, backup policy and a rehearsed restore are separate operational concerns. This interface does not establish that a backup or production recovery rehearsal has completed.

API

GET /api/v1/audit requires a current named owner or administrator in the selected workspace. source is EVENTS, CRM or SIGNATURES; optional filters are kind, recordId, from, through, after and limit (at most 100).

GET /api/v1/account/activity derives identity from the signed-in session, accepts optional kind, after and limit, and accepts no target account ID. Both endpoints are private, use current authorization and return no-store responses.