Common security uses
Verify a user's access
“Did Alice ever access this resource?” Filter by actor.
Detect unusual sign-ins
Sign-ins from new geographic regions, new IPs, or new device fingerprints.
Detect privilege escalation
Role changes outside expected workflow.
Track destructive actions
Deletes, especially bulk deletes. Helpful for “who deleted X?” questions.
App-level audit logs
For domain-meaningful actions in the apps you build (e.g., “sent invoice”, “deleted account”), implement application-level audit logs:Compliance
Audit logs satisfy a major portion of SOC 2, GDPR, and HIPAA requirements around access tracking. Pair with Data export and Account deletion for the rest.Related
Workspace audit logs
What’s logged + retention.
Compliance
Compliance use of audit data.
Data modeling
App-level audit table pattern.
