Report Audit Logs

Overview

The Audit Logs tab in the Reports module gives you a complete, timestamped record of every action taken on your report templates and generated reports. Use it to track who made changes, what changed, and when — and to compare versions of a report side by side when you need to understand exactly what shifted between runs.

Audit Logs are split into two sections: Template (covering all changes to report templates) and Report (covering all actions on generated reports). Both support filtering by action type, searching by name, restricting results to a date range, and exporting the full log to CSV.


Step 1 — Navigate to Audit Logs

Click the Reports icon in the left sidebar to expand the Reports section. Click Audit Logs. The All Reports page opens with the Audit Logs tab active.


Step 2 — Choose a Log Type

At the top of the Audit Logs view, two toggle buttons let you switch between log types:

  • Template: Records every change made to report templates — edits, lock status changes, access changes, and ownership transfers.
  • Report: Records every action taken on generated reports — generation, edits, regenerations, restores, and deletions.

Click the button for the log type you want to review. The table below updates immediately.



I. Template Audit Log

The Template audit log tracks every change to your report templates in the workspace. It covers content edits, access control changes, and lock status updates.


Step 3 — Review the Template Log Columns

The Template log table contains the following columns:

Column

Description

When

The exact date and time the action occurred. Click the column header to sort ascending or descending.

Template

The name of the template the action was performed on.

Action

A color-coded badge identifying what happened (see action types below).

Actor

The team member who performed the action.

Version

The template version affected, if applicable. Lock and access changes show a dash here since they do not create a new version.

What Changed

A View Changes link that opens a detail panel for that log entry.

Template action badges:

Badge

Color

Description

Created

The template was created for the first time.

Edited

The template content was edited and saved.

Reverted

A previous version of the template was restored.

Locked

Green

The template's lock status was enabled.

Unlocked

Red

The template's lock status was disabled.

Access changed

Yellow

A change was made to the template's access settings (co-editors or permissions).

Added co-editor

A co-editor was added to the template.

Removed co-editor

A co-editor was removed from the template.

Transferred ownership

Ownership of the template was transferred to another team member.


Step 4 — Filter Template Log by Action Type

Click the Filter by dropdown (default: All Actions) and select the action type you want to focus on. The table updates to show only entries matching that action. Available filter options are: All Actions, Created, Edited, Reverted, Locked, Unlocked, Added co-editor, Removed co-editor, and Transferred ownership.


Step 5 — Filter by Date Range

Click the Start date field to open a calendar picker. Select the beginning of the date range you want to review. Then click the End date field and select the end of the range. The table filters to show only entries within that window. Leave either field blank to leave that bound open-ended.


Step 6 — Search the Template Log

Click the Search by Template name bar and type the name of the template you want to look up. The table filters in real time as you type.


Step 7 — View Changes for a Template Entry

Click View Changes in the What Changed column for any log entry. A detail panel slides in from the right showing:

Field

Description

Template name

The name of the template the action affected.

Timestamp

The exact date and time of the action, plus a relative timestamp (e.g., "6 minutes ago").

Actor

The team member who performed the action.

Time Stamp

A precise timestamp for the action.

Version

The version number involved, if applicable. Shown as a dash for non-version actions.

Related to

The engagement or module the template is associated with, if applicable.

What Changed

A summary of the specific change that was made. For lock status changes, this shows the new state: Locked (red) or Unlocked (green). For access changes, it describes the access modification. For edits, it shows the content that changed.

Close the panel by clicking the X button in the top-right corner of the panel.


Step 8 — Export the Template Log to CSV

Click the Export CSV button in the top-right corner of the log. The button shows Exporting... while the file is being prepared. When the download is ready, an Export ready success notification appears at the bottom of the screen and the file downloads automatically. The CSV includes all entries currently visible with your active filters applied.



II. Report Audit Log

The Report audit log tracks every action taken on generated reports in the workspace — from the moment a report is first created through every regeneration, edit, and version restore.


Step 9 — Switch to the Report Log

Click the Report button at the top of the Audit Logs view. The table switches to the Report audit log. The columns are the same as the Template log but the Template column is replaced by Report, and the Version column now shows the report version number (v1, v2, v3...) for each action.


Step 10 — Review the Report Log Columns

Column

Description

When

The exact date and time of the action.

Report

The name of the report file the action was performed on.

Action

A color-coded badge identifying what happened (see action types below).

Actor

The team member who performed the action.

Version

The version number of the report at the time of the action (v1, v2, v3...).

What Changed

A View Changes link that opens a detail panel for that log entry.

Report action badges:

Badge

Color

Description

Generated

Green

The report was created for the first time.

Edited

Orange

The report was manually edited after generation.

Regenerated

Blue/Cyan

The report was re-run using the same template and scope, producing a new version.

Restored

A previous version of the report was restored as the current version.

Deleted

The report was deleted from the workspace.


Step 11 — Filter Report Log by Action Type

Click the Filter by dropdown and select the action type you want to see. Available options for the Report log are: All Actions, Generated, Edited, Regenerated, Restored, and Deleted. The table updates immediately.


Use the Start date and End date pickers to restrict the log to a specific time window, and use the Search by Report name bar to filter by report name. These controls work the same way as in the Template log and can be combined — for example, filtering to Regenerated actions within a specific date range for a specific report.


Step 13 — View Changes for a Report Entry

Click View Changes for any Report log entry. The detail panel shows:

Field

Description

Report name

The name of the report file.

Timestamp

The exact date and time of the action, plus a relative timestamp.

Actor

The team member who performed the action.

Time Stamp

A precise timestamp.

Version

The version transition for this action (e.g., v7 → v8).

Related to

The engagement, scan, or module that generated this report.

The What Changed section contains two sub-sections:

PDF regenerated: Shows the version transition as colored badges — the old version (red) and the new version (green) with an arrow between them. This confirms which version was produced by this action.

Findings: Summarizes whether any finding-level changes were included in this action. If no findings changed between versions, it shows: "No finding changes detected in this regeneration."

For entries where content did change, this section describes what was added, removed, or modified at the finding level.


Step 14 — Compare a Version with the Current Report

When viewing a report audit log entry, click the Compare with current button at the top of the What Changed section. A full-screen diff modal opens.


Step 15 — Comparing with the current version

The diff modal is titled [Version] vs current and shows a line-by-line comparison of the two report versions. Use the two view mode buttons in the top-right:

Mode

Description

Side by side

Displays the older version on the left and the current version on the right. Removed content is highlighted in red; added content is highlighted in green.

Inline

Displays both versions merged in a single column, with dual line numbers (old:new) and red/green highlights inline. Useful for following changes in sequence without switching panels.

Click Close or the X button to dismiss the modal and return to the View Changes panel.


Step 16 — Export the Report Log to CSV

Click Export CSV in the top-right corner of the Report log to download the current filtered view as a CSV file. The export includes all columns: When, Report, Action, Actor, Version, and a summary of what changed for each entry.


Tips

Use the Template log to investigate unexpected template changes. If a report looks different from a previous run, check the Template log first — a lock, edit, or version revert may have changed the template between runs.

The Version column in the Report log tells the full history at a glance. Each Regenerated or Edited action increments the version number. If you see v8 in the log and the current report is on v8, you can trace every step from v1 by reading the log from bottom to top.

Combine filters for precise investigations. Filter by action type and date range together to narrow to exactly what you need — for example, all "Edited" actions on a specific report this month, or all "Transferred ownership" events across your templates in the past quarter.

Export CSV before running investigations outside Strobes. If you need to share an access change record with a compliance reviewer or incident response team, export the filtered Template log to CSV and share the file. The exported data retains actor identities, timestamps, and action details.

"Compare with current" works from any historical version. You can click View Changes on any row in the Report log — not just the most recent — and compare that historical version against today's current report. This makes it easy to pinpoint exactly when a specific change was introduced.

Lock and unlock events don't increment the Version column. In the Template log, lock, unlock, and access change entries show a dash in the Version column because these actions do not change the template content. Only edits and reverts produce a new version.

Last updated: 9/11/26, 6:39 AM