Audit logs
A record of admin actions in the workspace, kept until the account is deleted and never edited.
Last update:
Audit logs records administrative actions taken in this workspace, and only workspace Admin members can read it.
Entries are never edited or deleted. Unlike browser reports, which expire after 90 days, audit entries are kept until the account is deleted.
An automated event shows System as the actor rather than a person. Each entry carries the action key, the target and its id, the event id, and any additional metadata, which is what you need when correlating with your own logs.
Script review decisions are the exception. Justifications and rejections are recorded in the compliance change ledger rather than here, and that ledger is the PCI DSS artefact for script decisions. For more information, refer to Justifying scripts.
Each row carries an actor, an action, and a timestamp:

Next steps
Two-factor enforcement
Require every workspace member to have two-factor authentication. What happens to members who do not, and the one prerequisite before turning it on.
Data retention
Browser reports are kept 90 days, fixed and not configurable. Compliance decisions and audit logs are kept until the account is deleted.