Audit log
Being able to trace "who changed what and when" is what makes incident investigation and internal controls possible. Major actions in your organization are recorded together with the time, actor, and client IP, so you can check the exact history when you need it.
What is recorded
- Authentication events (login, etc.)
- Scan started/completed/failed
- Setting changes, member/role changes
- Finding handling (false positive / accepted risk) and other key actions
Each record includes the actor, the time, and the client IP address.

Scope
The audit log is isolated per organization. Admins can only view their own organization's logs.