Skip to main content
Audit logs are the forensic record of what happened in your workspace. Use them for security review, compliance, and debugging. vly logs every meaningful workspace action — see Workspace → Audit logs for the full list of event types and retention.

Common security uses

Verify a user's access

“Did Alice ever access this resource?” Filter by actor.

Detect unusual sign-ins

Sign-ins from new geographic regions, new IPs, or new device fingerprints.

Detect privilege escalation

Role changes outside expected workflow.

Track destructive actions

Deletes, especially bulk deletes. Helpful for “who deleted X?” questions.

App-level audit logs

For domain-meaningful actions in the apps you build (e.g., “sent invoice”, “deleted account”), implement application-level audit logs:
Insert from every meaningful mutation. See Architecture → data modeling.

Compliance

Audit logs satisfy a major portion of SOC 2, GDPR, and HIPAA requirements around access tracking. Pair with Data export and Account deletion for the rest.

Workspace audit logs

What’s logged + retention.

Compliance

Compliance use of audit data.

Data modeling

App-level audit table pattern.
Last modified on April 18, 2026