Reading the audit log
The audit log answers three questions in practice.
“Who changed this?”
Link to this headingFilter the Changes tab on the target — the user or role concerned — and read down. Each row shows the actor, the action, and the details; together with the timestamp that’s the whole sequence of events. Large changes (reconciliations, migrations) are marked as their own actions, so you can tell them apart from manual steps.
“Why wasn’t I allowed?”
Link to this headingWhen a user reports being blocked, open Denied attempts and filter on the person. The row shows exactly which permission was missing and on which route. From there the fix is either a role assignment or a direct grant on the user page — or concluding the block was correct.
“Who has seen what?”
Link to this headingSensitive views shows every lookup of private data — who, what kind of view, and when. Review the tab regularly; it’s the proof that elevated rights are used as intended.
If the record needs archiving, use the CSV export with the filters set — the file’s selection matches the screen.