Overview
Use AuditLog to make security, governance, configuration, and operational changes traceable without turning the component into a general collaboration feed.
Workspace activity
Select an event to mirror the interaction and confirmation path.
Aug 14, 2026
Aug 13, 2026
Selected: No item selected
Anatomy
Each event combines an outcome marker, actor-action statement, affected target, timestamp, and optional evidence in a chronological rail.
Fields: customer_email- 1Date group
Segments chronology into scannable localized dates.
- 2Event marker
Identifies event type or outcome while the rail preserves sequence.
- 3Event statement
Connects the actor, action, and affected target.
- 4Timestamp
Provides a visible time and machine-readable value.
- 5Evidence
Adds a reason, changed value, or policy detail when useful.
When to use
Use AuditLog when people must establish who or what changed a governed resource and when it happened.
Recommended
- Trace administrative changes
Record access, ownership, policy, configuration, and lifecycle events.
- Support investigation
Expose stable event identity and relevant evidence for review.
- Explain automated decisions
Represent services and policy engines as actors with clear outcomes.
When not to use
AuditLog is not a substitute for social feeds, notifications, or dense analytical exploration.
Avoid
- Do not use as a social feed
Use a purpose-built activity feed for comments, reactions, and collaboration.
- Do not replace notifications
Use Toast or a notification center for time-sensitive awareness.
- Do not force large-scale analysis
Use DataTable when events need columns, bulk scanning, sorting, or export.
Variants
Container and scale adapt the same event grammar to page regions and elevated review surfaces.
Plain
Integrates into a page region with an existing boundary.
Bordered
Defines a standalone audit region.
Raised
Supports an elevated review or investigation surface.
Sizes
Small, medium, and large tune spacing and marker scale.
States
AuditLog separates data-resolution states from semantic event outcomes.
| State | Trigger | Visual response | Interaction |
|---|---|---|---|
| Populated | Events are available | Grouped chronological list | Inspect or open entries |
| Interactive entry | href or selection handler exists | Hover and focus surface | Opens event detail |
| Loading | Events are resolving | Progress and loading message | Entries are withheld |
| Empty | No events exist | Neutral no-activity message | No event action |
| Error | Retrieval fails | Assertive error feedback | Recovery remains application-owned |
Behavior
AuditLog owns chronology and event presentation while applications own retrieval, authorization, pagination, filtering, and retention.
Date grouping
Events retain their supplied order and group under localized date headings.
Time formatting
Visible time can be localized or made relative without losing datetime data.
Actor identity
People, integrations, and services use the same explicit actor slot.
Inspection
An href or selection handler makes the complete event target actionable.
Accessibility
AuditLog uses date sections, ordered lists, headings, and time elements so chronology remains understandable without visual markers.
- Keep event statements complete when read without the marker or timeline rail.
- Use a real time element with an ISO-compatible datetime value.
- Preserve a logical newest-first or oldest-first order and document the chosen convention.
- Give custom actor visuals and event markers appropriate text alternatives only when they add meaning.
- Do not communicate event outcome through color alone.
- Ensure an interactive event has one clear focus target and a descriptive accessible name.
Content guidelines
Event language should be factual, durable, and consistent enough to support investigation months later.
Name the actor
Use a recognizable person, integration, or service identity.
Policy service
Use past-tense actions
Describe the completed event directly.
changed the owner of
Name the target
Identify the affected resource, not just its type.
Cloud migration
Record evidence
Add relevant changed values or policy reasons without interpretation.
Owner: Priya Shah → Maya Chen
Examples
Use examples that mirror operational review and incident workflows.
Review workflow with immutable audit context
Open a selected event and keep a stable action log for investigators.
Aug 14, 2026
Aug 13, 2026
Selected: No item selected
Props / API
AuditLog extends div attributes; AuditLogEntry defines event identity, actor, action, target, timestamp, evidence, marker, and optional destination.
Props