# Audit logs (/en/docs/platform/security/audit-log)





**Audit logs** records administrative actions taken in this workspace, and only workspace **Admin** members can read it.

Entries are never edited or deleted. Unlike browser reports, which expire after 90 days, audit entries are kept **until the account is deleted**.

An automated event shows **System** as the actor rather than a person. Each entry carries the action key, the target and its id, the event id, and any additional metadata, which is what you need when correlating with your own logs.

Script review decisions are the exception. Justifications and rejections are recorded in the compliance change ledger rather than here, and that ledger is the PCI DSS artefact for script decisions. For more information, refer to [Justifying scripts](/en/docs/platform/features/pci-dss/justifying-scripts).

Each row carries an actor, an action, and a timestamp:

<img alt="The workspace audit log, with the All actions and All targets filters and a date range switch" src="__img0" width="1235" height="455" />

## Next steps [#next-steps]

* [Roles and permissions](/en/docs/platform/team/roles-and-permissions)
* [Data retention](/en/docs/platform/security/data-retention)
