CaseWizard

Audit logs

Review user activity, sign-ins, and sensitive actions.

Audit logs provide a searchable history of actions across your firm, including sign-ins, data changes, PII reveal events, administrative changes, and integration activity.

Review activity

Open Administration → Audit logs.
Filter by time range, user, resource, action, IP address, or browser context.
Review the matching entries and sort your investigation by the newest activity.
Open a row to view its details, including duration and request context when available.
Export the results to Excel for compliance review when your permissions allow it.

Use summaries and detail

Audit entries include concise summaries to help you understand activity quickly. Open an entry when you need more context. Depending on the event, detail can include duration, client name, browser information, user agent, IP address, location, parameters, and exception information.

Use the summary to identify the relevant event, then confirm the details before documenting a finding. A missing detail does not necessarily mean that the action did not occur. Some fields are available only when the event supplies them.

What gets logged

  • Authentication and session events
  • Case and contact updates
  • SSN/DL reveal actions on people records
  • Administrative changes
  • Integration and document actions, as configured

Recent releases also added a live audit view and richer columns. The audit log can therefore support both an immediate review of current activity and a later compliance investigation.

Audit access is permission-controlled. If you cannot open the audit area or export results, ask an administrator to review your role.

Investigate a concern

Start with a narrow time range and the affected user or resource. Add an action or IP filter when you need to distinguish a specific event. Open each relevant row and record the summary and available request context according to your firm's investigation process.

For a sensitive-person-record review, filter for the relevant people activity and look specifically for PII reveal events. For a login review, filter by authentication activity and compare the user, time, browser, IP address, and location when those fields are available.

Export and handle results

Export only the entries needed for the compliance or operational task. Audit exports may contain user, client, or request information. Store them in an approved location and apply your firm's retention and access rules.

Next steps

On this page