Audit log
Also called: audit trail, activity log, event history.
A list of who did what and when, written as it happens and never edited, like "Ana changed the plan to Pro on 3 Sep at 14:02". Teams use it to answer "who changed this?" and for security reviews.
The customers table keeps only the latest plan. The audit log keeps every change: who, what, when, before → after.
Log entries: 0 · Edits refused: 0
Customer 42 is on the Basic plan. Nothing has changed yet, so the audit log is empty.
Say it in a prompt
Write an audit log entry for every permission change: actor, action (role.granted or role.revoked), target user, old and new role, time and IP address. Store entries append-only, never update or delete them, and add GET /api/audit-events with actor, action and date filters for admins. Vague vs precise prompt
Vague prompt
keep track of changes in the admin panel Typical resultAdds an updated_at column and maybe a console.log. You can see that a record changed, but not who changed it, what it was before, or any earlier change.
Precise prompt
Add an audit log: for every create, update and delete in the admin panel, insert a row into audit_events with actor_id, action, target type and id, before and after values, IP address and time. The table is insert-only, kept for 1 year, and shown on a filterable Activity page. Typical resultAdmins open Activity, filter by person or record, and see lines like "Ana changed plan from Basic to Pro, 3 Sep 14:02" for every change.
Seen on
- GitHub: An organization's audit log records the actor, the action (like repo.create) and the time, and keeps the last 180 days.
You might describe it as
- history of who changed what
- see which admin removed the user
- a record of every change for security
Not to be confused with
- Soft delete
An audit log records who did what and when; a soft delete keeps the deleted row itself so it can be restored.