Use the audit log and export workspace data
Trace administrative events and download a portable workspace record.
The Audit log preserves administrative and security-relevant events, while the workspace export downloads material workspace data as JSON. The log explains an event; the live source record remains the authority for current state.
Before you start
• Both surfaces require workspace admin access.
• Choose a secure destination for exports because they can contain projects, vendors, register records and audit information.
Step by step
1. Review audit events
Open Settings → Audit log. Read the actor, action, target and time, then inspect any recorded changes or reason.
2. Interpret deleted targets
Deleted items can appear as struck-through tombstones so the event remains understandable even though the live record no longer exists.
3. Correlate with the source
Open the related current record where available and compare it with surrounding events. Use timestamps and actors to reconstruct sequence, not to infer content the event did not record.
4. Download the workspace export
Go to Settings → Workspace and choose the export action under Your data. Save the generated JSON file to an approved location.
5. Protect and dispose of the file
Limit access, use the export only for the stated governance purpose and delete working copies according to your retention policy.
What happens next
• Use the audit evidence during access reviews, incident investigation and governance checks.
• A workspace export is a point-in-time copy; generate a new one when current data is required.
Troubleshooting
An expected event is not visible
Confirm the action is one of the audited event types and that you are viewing the correct workspace. Operational activity may instead appear in workspace or project Activity.
The export will not download
Allow downloads for the site, retry once and check available disk space. If it still fails, report the time and workspace without attaching sensitive data.
A deleted target cannot be opened
This is expected. Use the tombstone name and audit details; deletion means there is no current source page.
Related guides
Related articles
Still stuck? Contact us →
