Home/Help Center/Audit log

Account, billing and security

Read the audit log

What the VGraple CRM audit log records (messages, broadcasts, templates, members, settings, exports), who can read it, how to filter it, and how to use it during an incident.

By Chirag Darji · Updated 27 Aug 2026 · 5 min read

On this page
  1. Before you start
  2. Steps
  3. What is recorded
  4. Reading an entry
  5. Settings and options
  6. Troubleshooting
  7. What the log does not contain
  8. Who should read it and how often
  9. Reading it on the Android app
  10. Common questions the log answers
  11. Retention and export
  12. Using the log during an incident
Team members in VGraple CRM with owner, admin and agent roles and their permissions

The audit log is the append-only record of who did what in your VGraple CRM workspace: sends, broadcasts, template and flow changes, contact edits, member and role changes, settings updates and exports, each with the actor, the time and the IP address. It answers the questions that come up during an incident or an audit, and it records support actions by VGraple staff against your organisation as well.

Audit log

  1. 1Open Audit Log from the sidebar (on
  2. 2Use the date range and the action
  3. 3Click an entry to see the details
  4. 4Look for the super admin flag on
  5. 5Export the filtered list when you need
The steps on this page, in order.

Before you start

  • You need the audit view permission: Owner, Admin, or a custom role with it.
  • Entries are recorded from the moment the workspace was created; there is nothing to enable.

Steps

  1. Open Audit Log from the sidebar (on the Android app: More, then Audit trail).
  2. Use the date range and the action filter to narrow the list, for example to broadcast sends in the last week or member role changes this month.
  3. Click an entry to see the details: the actor, their role at the time, the object (contact, conversation, template, flow, member or setting), the IP address and a summary of the change.
  4. Look for the super admin flag on entries performed by VGraple support inside your organisation.
  5. Export the filtered list when you need a copy outside the app.

Profile settings in VGraple CRM with two-factor authentication

What is recorded

AreaActions
ContactsCreate, update, delete, block, merge
ConversationsStart, resolve, reopen, assign, snooze
MessagesSend free-form, send template, send media, send CTA URL
BroadcastsCreate, send, retry, cancel, clone, retarget, delete, export
FlowsCreate, delete, toggle on or off
TemplatesCreate, update, delete, clone, translate, appeal, toggle, bulk submit from the gallery
MembersInvite, role change, remove, profile edit
SettingsOrganisation settings update, Meta Conversion Tracking update, Payment Collection update
ExportsLeads export, email export

Reading an entry

Each entry shows the action name, the actor's name and email, whether the actor was a platform super admin, the target object with a link where it still exists, the IP address and the timestamp in your workspace time zone. For settings changes, the entry summarises which fields changed without revealing secret values.

Settings and options

SettingWhat it doesDefault
Date rangeLimits the list to a periodLast 30 days
Action filterShows one action typeAll
Actor filterShows one member's actionsAll
ExportDownloads the filtered listOn demand

Troubleshooting

SymptomLikely causeFix
Audit Log is missing from the sidebarYour role lacks audit viewAsk an Owner or Admin
An entry shows a super admin as the actorVGraple support acted in your organisation, usually during a support thread you openedCheck the support thread; contact support if unexpected
A deleted member's actions still showEntries are never removedExpected
Cannot find a message readReads are not loggedUse roles and teams to control visibility instead

What the log does not contain

Message content is not copied into the log; the entry links to the conversation instead, so reading a customer's words still requires the role and team scope to open it. Views and searches are not logged. Sign-ins are visible under organisation sessions rather than here, and Meta-side events (template approvals, quality changes) appear on the template and channel pages, not in the audit log. Automated actions taken by flows, sequences and rules are attributed to the automation rather than to a person, which is how you tell a bot's send from an agent's.

Who should read it and how often

Owners and admins should scan the log weekly at first and monthly once the team has settled: a quick pass filtered to broadcasts, exports and member changes takes five minutes and catches the things that matter. Supervisors do not need it for daily work because the inbox itself shows who replied to what. Auditors and clients of an agency can be given the export rather than a login.

Reading it on the Android app

Under More, then Audit trail, the same entries are listed newest first with the same filters, useful for a quick "who sent that" check away from the desk. Export is web-only.

Common questions the log answers

QuestionFilterWhat to read
Who sent that broadcast to the whole list?Action: broadcast.sendActor, audience size, template
Who changed the template wording before it was rejected?Action: template.updateActor and the before and after summary
Who exported the contact list last month?Actions: export.leads, export.emails, broadcast.exportActor, time, filter used
Who gave this person Admin?Action: member.role_changeActor, target member, old and new role
Did anyone from VGraple act in our account?Super admin flagThe linked support thread
Who turned the payment gateway on?Action: settings.payments.updateActor and time (values are never shown)

Retention and export

Entries are kept for the retention period stated in the DPA and are included in the data export you can request when leaving. Export the log monthly if your own policy needs a longer record; the CSV includes every column shown on screen.

Using the log during an incident

Start from the time the problem was noticed and work backwards: a broadcast that went to the wrong list shows the sender and the audience; a template that changed unexpectedly shows who edited it; a contact export shows who downloaded what. Combine the log with organisation sessions to see where the actor was signed in from, and with the roles reference to tighten permissions afterwards.

Frequently asked questions

Who can see the audit log?
Owners and Admins, and anyone with a custom role that grants audit view. It is under Audit Log in the sidebar and under More on the Android app as Audit trail.
What is recorded?
Contact changes, conversation actions, every send (free-form, template, media, CTA), broadcast actions including export, flow and template changes, member invites and role changes, settings updates including payment and Conversions API settings, and exports of leads and emails.
Are message reads logged?
No. The log records actions, not views. Conversation visibility is controlled by roles and teams.
Are support actions by VGraple staff logged?
Yes. Actions performed by a platform super admin inside your organisation are recorded against your organisation and flagged as super admin actions.
Can entries be deleted?
No. The log is append-only, and removing a member does not remove their entries.
Can I export it?
Yes, filtered by date, for your own records or an auditor.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.