The audit log shows what members did in your Workspace, together with who did it, when, on what, and from which IP address. It covers sign-ins, member and permission changes, API key issuance, connections to external services, broadcasts, data exports, and more. This article covers how to open the audit log, which actions are recorded, filtering and CSV export, and what to keep in mind when reading it.
What you need to view the audit log
Only Workspace administrators can view the audit log. General members don't see the "Audit log" menu, and opening the URL directly takes them back to the home screen.
- You are signed in to Lumo
- You are a Workspace administrator
Actions are recorded on every plan. There is no difference between plans.
Opening the audit log screen
The audit log opens from the left menu of the same screen as member settings.
- Open "Settings" in the navigation menu
- Select "Member Settings"
- Choose "Audit log" in the left menu
The list shows the newest actions first. The columns mean the following.
| Column | What it shows |
|---|---|
| Date | When the action happened |
| Actor | The name and email address of the member who did it. Actions through the public API show the API key name, and scheduled processing shows "System" |
| Category | The kind of action. There are nine: Sign-in, Members, API key, Connections, Messaging, Data, Billing, Workspace, and AI agent |
| Action | What was done. Successful actions and activations are green; failures, deletions, disconnections, and stops are red |
| Target | What the action was applied to, such as a member's email address, a broadcast title, or a LINE account name, as it was named at the time |
| Details | A short summary such as counts or what changed |
| Source IP | The IP address the action came from |
Click "Details" on a row to open a panel on the right with the values before and after the change, the IP address, the browser, and the event ID. Actor and target names are kept as they were at the time; renaming them later doesn't rewrite the log.
Which actions are recorded
The log records the actions an administrator would want to check, grouped by category.
| Category | Recorded actions |
|---|---|
| Sign-in | Signed in, sign-in failed, account locked, signed out, two-factor authentication enabled/disabled, password reset, email address changed |
| Members | Member invited, invitation resent, invitation cancelled, member joined, role changed, permissions changed, group changed, member deactivated/reactivated, password setup email sent, group created/updated/deleted |
| API key | API key issued |
| Connections | LINE account connected, LINE account settings updated, LINE account deleted/restored, external service connected/disconnected |
| Messaging | Broadcast sent, broadcast scheduled, broadcast schedule cancelled, broadcast deleted, test message sent, A/B test started/cancelled, message sent via API, workflow activated/deactivated |
| Data | CSV exported, import started/completed, import source created/updated/deleted, imported data purged, field created/updated/deleted, friend detail fields updated |
| Billing | Subscription started, plan changed, cancellation requested, subscription resumed, payment method changed/removed, billing switched to Lumo, contract information updated |
| Workspace | Workspace settings updated, Workspace deletion scheduled/cancelled, tracking domain updated/deleted |
| AI agent | Agent operation approved/rejected |
Sign-in records appear in every Workspace the member belongs to. Role and permission changes record the values before and after.
Changes to individual friends aren't in the audit log, because a single import can change tens of thousands of them at once. They're recorded as field changes or import runs instead.
Filtering and exporting a CSV
You can narrow the list by category and keyword, and download what's shown as a CSV.
| Control | What it does |
|---|---|
| "Category" | Narrows the list to one kind of action |
| Search box | Narrows the list to records whose target name, actor name, or email address contains the text |
| "Export CSV" | Downloads the records that match the current filters as a CSV. One download holds up to 10,000 records; narrow the list first if there are more |
Exporting the CSV is itself recorded, so the list also shows who took a copy of the audit log and when.
Retention and things to keep in mind
The audit log is kept for one year and can't be edited or deleted. Keep the following in mind when reading it.
- Records older than one year are deleted automatically. If you need older records, contact us through the inquiry form
- Records start from September 15, 2026. Earlier actions don't appear
- Actions performed in the CONNECT screens aren't in Lumo's audit log
- The source IP is the address used to reach Lumo. Depending on your office network or mobile carrier, the same member can show different addresses on different days
When things don't work
Common questions about the audit log and what to do.
| Situation | What to do |
|---|---|
| The "Audit log" menu doesn't appear | Only administrators see it. Ask a Workspace administrator if you need to check something |
| An action you're looking for isn't listed | Actions before September 15, 2026, actions in the CONNECT screens, and records older than one year don't appear. Changes to individual friends show up as field or import records instead |
| The CSV won't export | Downloads stop above 10,000 records. Narrow the list by category or keyword and try again |
| The same member shows a different IP address every time | Source addresses change with how the network is set up. This isn't an error |