Browse documentation

Audit log

Every action, who or what triggered it, and what happened to each person.

Why this exists. Changing someone's access is exactly the kind of event an auditor asks about six months later, usually on a day when nobody remembers doing it.

Jira → Apps → License Waste Manager → Audit LogIllustration

Audit Log

DashboardUsersAdmin RolesAPI TokensAutomationAudit LogSettings
WhenActionTriggered byRuleResult
1 Aug 2026 03:00Remove from groupruleReclaim dormant Jira Software seats29 success 0 failedView users
24 Jul 2026 14:22Suspend usermanual3 success 1 failedView users
Affected users — 24 Jul 2026 14:22
UserAccount IDResultError
Tomas Silva712020:d7a2…success
External Auditor557058:0f00…failedUser is managed by another organization

What each entry records

  • When it ran and what the action was — removed from group, added to group, revoked product access, suspended account, restored account.
  • Triggered by: Manual, with the administrator's name and avatar, or Automated, with the rule's name. An action whose actor could not be resolved says Actor not recorded rather than guessing.
  • Per-person outcome: account ID, display name, success, failure or skipped, and the reason text in either of the last two cases — including which protection list spared somebody.
  • Counts of successes, failures and skips, so a partial run is obvious at a glance.
  • The groups the action targeted.

Finding the entry you are looking for

  • Search reaches every entry's summary, rule name and target groups, and the matched term is highlighted where it hit — each surviving row shows why it survived.
  • Date: all, last 7 / 30 / 90 days, or a period with two dates.
  • Actor: the administrators who actually appear in the log, plus Automated for entries nobody clicked.
  • Status: Success, Partial — some people failed — or Failed.
  • Action, Trigger and Rule narrow by what ran and what asked for it.
  • The header counts both sides — 789 entries — showing 12 — so a narrow filter never reads as a small log, and Reset clears everything.

Show details expands one entry into its per-person rows: search for a person, filter by outcome — Changed, Failed or Skipped — and each name links to that account's page in admin.atlassian.com, so acting on what you find is one click.

Taking the evidence with you

  • Export CSV writes the log under exactly the filters on screen — the file holds what you were looking at, no more and no less, with the same columns the table shows.
  • Export these people (CSV), inside an expanded entry, writes that run's named people with each one's result and error — the attachment a licence-reduction ticket actually needs.
Entries are kept for 180 days, and there is no way to keep them longer
The audit trail is swept at the end of every scan: an entry older than 180 days is deleted, and so is its per-user detail, on the same horizon. That pairing is deliberate. An entry that outlived its detail would say “504 users affected” with no way left to see who they were — an audit trail decaying into a number. One horizon means a row is either fully answerable or gone.
Keep the evidence before it ages out
The audit entry is your proof that the seats you stopped paying for were released on a specific date. If a compliance review runs more than six months behind your clean-up, Export CSV the relevant entries somewhere outside the app while they are still there.

Something missing or wrong on this page? Tell us in the support portal or email contact@synapseoasis.com.