Report Audit Logs
Overview
The Audit Logs tab in the Reports module gives you a complete, timestamped record of every action taken on your report templates and generated reports. Use it to track who made changes, what changed, and when — and to compare versions of a report side by side when you need to understand exactly what shifted between runs.
Audit Logs are split into two sections: Template (covering all changes to report templates) and Report (covering all actions on generated reports). Both support filtering by action type, searching by name, restricting results to a date range, and exporting the full log to CSV.
Step 1 — Navigate to Audit Logs
Click the Reports icon in the left sidebar to expand the Reports section. Click Audit Logs. The All Reports page opens with the Audit Logs tab active.
Step 2 — Choose a Log Type
At the top of the Audit Logs view, two toggle buttons let you switch between log types:
- Template: Records every change made to report templates — edits, lock status changes, access changes, and ownership transfers.
- Report: Records every action taken on generated reports — generation, edits, regenerations, restores, and deletions.
Click the button for the log type you want to review. The table below updates immediately.
I. Template Audit Log
The Template audit log tracks every change to your report templates in the workspace. It covers content edits, access control changes, and lock status updates.
Step 3 — Review the Template Log Columns
The Template log table contains the following columns:
Column | Description |
|---|---|
When | The exact date and time the action occurred. Click the column header to sort ascending or descending. |
Template | The name of the template the action was performed on. |
Action | A color-coded badge identifying what happened (see action types below). |
Actor | The team member who performed the action. |
Version | The template version affected, if applicable. Lock and access changes show a dash here since they do not create a new version. |
What Changed | A View Changes link that opens a detail panel for that log entry. |
Template action badges:
Badge | Color | Description |
|---|---|---|
Created | — | The template was created for the first time. |
Edited | — | The template content was edited and saved. |
Reverted | — | A previous version of the template was restored. |
Locked | Green | The template's lock status was enabled. |
Unlocked | Red | The template's lock status was disabled. |
Access changed | Yellow | A change was made to the template's access settings (co-editors or permissions). |
Added co-editor | — | A co-editor was added to the template. |
Removed co-editor | — | A co-editor was removed from the template. |
Transferred ownership | — | Ownership of the template was transferred to another team member. |
Step 4 — Filter Template Log by Action Type
Click the Filter by dropdown (default: All Actions) and select the action type you want to focus on. The table updates to show only entries matching that action. Available filter options are: All Actions, Created, Edited, Reverted, Locked, Unlocked, Added co-editor, Removed co-editor, and Transferred ownership.
Step 5 — Filter by Date Range
Click the Start date field to open a calendar picker. Select the beginning of the date range you want to review. Then click the End date field and select the end of the range. The table filters to show only entries within that window. Leave either field blank to leave that bound open-ended.
Step 6 — Search the Template Log
Click the Search by Template name bar and type the name of the template you want to look up. The table filters in real time as you type.
Step 7 — View Changes for a Template Entry
Click View Changes in the What Changed column for any log entry. A detail panel slides in from the right showing:
Field | Description |
|---|---|
Template name | The name of the template the action affected. |
Timestamp | The exact date and time of the action, plus a relative timestamp (e.g., "6 minutes ago"). |
Actor | The team member who performed the action. |
Time Stamp | A precise timestamp for the action. |
Version | The version number involved, if applicable. Shown as a dash for non-version actions. |
Related to | The engagement or module the template is associated with, if applicable. |
What Changed | A summary of the specific change that was made. For lock status changes, this shows the new state: Locked (red) or Unlocked (green). For access changes, it describes the access modification. For edits, it shows the content that changed. |
Close the panel by clicking the X button in the top-right corner of the panel.
Step 8 — Export the Template Log to CSV
Click the Export CSV button in the top-right corner of the log. The button shows Exporting... while the file is being prepared. When the download is ready, an Export ready success notification appears at the bottom of the screen and the file downloads automatically. The CSV includes all entries currently visible with your active filters applied.
II. Report Audit Log
The Report audit log tracks every action taken on generated reports in the workspace — from the moment a report is first created through every regeneration, edit, and version restore.
Step 9 — Switch to the Report Log
Click the Report button at the top of the Audit Logs view. The table switches to the Report audit log. The columns are the same as the Template log but the Template column is replaced by Report, and the Version column now shows the report version number (v1, v2, v3...) for each action.
Step 10 — Review the Report Log Columns
Column | Description |
|---|---|
When | The exact date and time of the action. |
Report | The name of the report file the action was performed on. |
Action | A color-coded badge identifying what happened (see action types below). |
Actor | The team member who performed the action. |
Version | The version number of the report at the time of the action (v1, v2, v3...). |
What Changed | A View Changes link that opens a detail panel for that log entry. |
Report action badges:
Badge | Color | Description |
|---|---|---|
Generated | Green | The report was created for the first time. |
Edited | Orange | The report was manually edited after generation. |
Regenerated | Blue/Cyan | The report was re-run using the same template and scope, producing a new version. |
Restored | — | A previous version of the report was restored as the current version. |
Deleted | — | The report was deleted from the workspace. |
Step 11 — Filter Report Log by Action Type
Click the Filter by dropdown and select the action type you want to see. Available options for the Report log are: All Actions, Generated, Edited, Regenerated, Restored, and Deleted. The table updates immediately.
Step 12 — Filter by Date Range and Search
Use the Start date and End date pickers to restrict the log to a specific time window, and use the Search by Report name bar to filter by report name. These controls work the same way as in the Template log and can be combined — for example, filtering to Regenerated actions within a specific date range for a specific report.
Step 13 — View Changes for a Report Entry
Click View Changes for any Report log entry. The detail panel shows:
Field | Description |
|---|---|
Report name | The name of the report file. |
Timestamp | The exact date and time of the action, plus a relative timestamp. |
Actor | The team member who performed the action. |
Time Stamp | A precise timestamp. |
Version | The version transition for this action (e.g., v7 → v8). |
Related to | The engagement, scan, or module that generated this report. |
The What Changed section contains two sub-sections:
PDF regenerated: Shows the version transition as colored badges — the old version (red) and the new version (green) with an arrow between them. This confirms which version was produced by this action.
Findings: Summarizes whether any finding-level changes were included in this action. If no findings changed between versions, it shows: "No finding changes detected in this regeneration."
For entries where content did change, this section describes what was added, removed, or modified at the finding level.
Step 14 — Compare a Version with the Current Report
When viewing a report audit log entry, click the Compare with current button at the top of the What Changed section. A full-screen diff modal opens.
Step 15 — Comparing with the current version
The diff modal is titled [Version] vs current and shows a line-by-line comparison of the two report versions. Use the two view mode buttons in the top-right:
Mode | Description |
|---|---|
Side by side | Displays the older version on the left and the current version on the right. Removed content is highlighted in red; added content is highlighted in green. |
Inline | Displays both versions merged in a single column, with dual line numbers (old:new) and red/green highlights inline. Useful for following changes in sequence without switching panels. |
Click Close or the X button to dismiss the modal and return to the View Changes panel.
Step 16 — Export the Report Log to CSV
Click Export CSV in the top-right corner of the Report log to download the current filtered view as a CSV file. The export includes all columns: When, Report, Action, Actor, Version, and a summary of what changed for each entry.
Tips
Use the Template log to investigate unexpected template changes. If a report looks different from a previous run, check the Template log first — a lock, edit, or version revert may have changed the template between runs.
The Version column in the Report log tells the full history at a glance. Each Regenerated or Edited action increments the version number. If you see v8 in the log and the current report is on v8, you can trace every step from v1 by reading the log from bottom to top.
Combine filters for precise investigations. Filter by action type and date range together to narrow to exactly what you need — for example, all "Edited" actions on a specific report this month, or all "Transferred ownership" events across your templates in the past quarter.
Export CSV before running investigations outside Strobes. If you need to share an access change record with a compliance reviewer or incident response team, export the filtered Template log to CSV and share the file. The exported data retains actor identities, timestamps, and action details.
"Compare with current" works from any historical version. You can click View Changes on any row in the Report log — not just the most recent — and compare that historical version against today's current report. This makes it easy to pinpoint exactly when a specific change was introduced.
Lock and unlock events don't increment the Version column. In the Template log, lock, unlock, and access change entries show a dash in the Version column because these actions do not change the template content. Only edits and reverts produce a new version.