> ## Documentation Index
> Fetch the complete documentation index at: https://vlyai-1c28d863.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit logs (security)

> What gets logged, how to access, how to export. Compliance use cases.

Audit logs are the **forensic record** of what happened in your workspace. Use them for security review, compliance, and debugging.

vly logs every meaningful workspace action — see [Workspace → Audit logs](/features/workspace/audit-logs) for the full list of event types and retention.

## Common security uses

<CardGroup cols={2}>
  <Card title="Verify a user's access" icon="user-check">
    "Did Alice ever access this resource?" Filter by actor.
  </Card>

  <Card title="Detect unusual sign-ins" icon="alert-triangle">
    Sign-ins from new geographic regions, new IPs, or new device fingerprints.
  </Card>

  <Card title="Detect privilege escalation" icon="shield-alert">
    Role changes outside expected workflow.
  </Card>

  <Card title="Track destructive actions" icon="trash">
    Deletes, especially bulk deletes. Helpful for "who deleted X?" questions.
  </Card>
</CardGroup>

## App-level audit logs

For domain-meaningful actions in **the apps you build** (e.g., "sent invoice", "deleted account"), implement application-level audit logs:

```typescript theme={null}
audits: defineTable({
  actorId:    v.id("users"),
  action:     v.string(),
  entityType: v.string(),
  entityId:   v.string(),
  before:     v.optional(v.any()),
  after:      v.optional(v.any()),
  at:         v.number(),
}).index("by_entity", ["entityType", "entityId"])
  .index("by_actor", ["actorId"])
```

Insert from every meaningful mutation. See [Architecture → data modeling](/architecture/data-modeling#audit-trail).

## Compliance

Audit logs satisfy a major portion of SOC 2, GDPR, and HIPAA requirements around access tracking. Pair with [Data export](/security/data-export) and [Account deletion](/security/account-deletion) for the rest.

## Related

<CardGroup cols={3}>
  <Card title="Workspace audit logs" icon="scroll-text" href="/features/workspace/audit-logs">
    What's logged + retention.
  </Card>

  <Card title="Compliance" icon="award" href="/security/compliance">
    Compliance use of audit data.
  </Card>

  <Card title="Data modeling" icon="database" href="/architecture/data-modeling">
    App-level audit table pattern.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.