# Audit Log

Organization-level audit events that record who did what in your Factory organization.

The Factory audit log records organization-level events so you can track who did what in your organization. Each event captures **who** acted, **where** the action originated, **what** was affected, and structured details about the change.

<Info>
  **Enterprise Feature** -- The audit log is available to **Enterprise organization owners only**. Owners can view the audit log in the Factory web app under Team Settings, or via the public API.
</Info>

---

## Overview

Every audit event includes:

- **Actor** -- the user or service principal who initiated the action (or `null` for system-initiated events).
- **Source** -- the surface that originated the event (e.g. web settings pages, public API, identity provider webhooks).
- **Target** -- identifiers for the affected entity (e.g. user, service account, integration).
- **Payload** -- structured, event-specific details, such as IDs, settings values, and enum values, never secrets.
- **Timestamp** -- ISO 8601 timestamp of the event.

---

## Event categories

Audit events cover the following categories of organization activity:

- **Usage limits** -- per-user token usage limit changes.
- **Usage alerts** -- organization monthly alert threshold and alert email setting changes.
- **Membership** -- role changes, invitations, and member removals.
- **API keys** -- creation and deletion of user and service-account API keys.
- **Service accounts** -- creation, modification, deletion, and credential/grant changes.
- **Integrations** -- connection, disconnection, configuration, and availability toggles.
- **Organization lifecycle** -- creation and deactivation of organizations.
- **Managed settings** -- updates to org-managed settings (with revision tracking for before/after diffing).
- **Analytics settings** -- updates to org-wide analytics preferences.

## Organization usage alert settings

Changes to the [organization usage alert settings](/factory-app/settings#organization-usage-alerts) record an `organization_monthly_usage_settings_change` event with source `web_settings_usage`. The event identifies the Owner or Manager who made the change and includes:

| Payload field | Meaning |
| --- | --- |
| `previousMonthlyLimitFsc` | Previous monthly alert threshold in FSC, or `null` if none was set. |
| `monthlyLimitFsc` | New monthly alert threshold in FSC, or `null` if removed. |
| `previousAlertEmailsEnabled` | Whether organization alert emails were enabled before the change. |
| `alertEmailsEnabled` | Whether organization alert emails are enabled after the change. |

Despite the `Limit` field names, these values describe an informational alert threshold, not an enforced usage cap. The event records settings changes, not threshold crossings or email deliveries. Saving unchanged settings does not create an event.

<RelatedLinks>
  <RelatedLink href="/enterprise/compliance-audit-and-monitoring" title="Compliance & Audit">
    See how audit events fit into your broader audit, compliance, and monitoring posture.
  </RelatedLink>
  <RelatedLink href="/enterprise/telemetry" title="Telemetry & Analytics">
    Export OTEL telemetry and read the hosted Analytics API for fine-grained activity data.
  </RelatedLink>
</RelatedLinks>
