Browse the manual

Audit log

Read-only security and compliance event history for your Made with Pepper installation.

On this page

For: owners and admins monitoring security and compliance. Covers: what the audit log records, how to access it, and how to filter events.

Made with Pepper records security and compliance events in a read-only audit log. You cannot edit or delete events.

Audit log with actor, event and time filters

Accessing the audit log

Go to Settings > Audit log. Owners and admins see every event.

An accountant opens the audit log from Your profile and sees only their own events. The page says "Your own actions in Made with Pepper, newest first." It has no Actor filter and names no other person. Employees have no audit log.

The list shows each event with its name in your language, the actor, the severity, the IP address and the date. The date and the time use the company's date format and time format. Chips above the list filter by severity and show the count of each. Click View on a row to open Event details. It shows the event code (for example customer.created), request ID, record, user agent and metadata.

Recorded events

Authentication

  • User logged in
  • User logged out
  • Failed login attempts
  • Password reset requested and password reset
  • Password changed in the profile

Settings

  • Settings updated (with before/after metadata)
  • Settings section reset to defaults
  • Email template updated or reset, with its language

Users

  • User invited, invitation sent again or revoked
  • User created from an invitation, updated, deactivated, reactivated or deleted
  • Profile updated
  • Ownership transferred

Documents

  • Document created or updated, for every document type (events invoice.created and invoice.updated)
  • Document finalized (with document number)
  • Quote accepted or declined by the customer
  • Quote or pro forma converted to an invoice
  • Document cancelled, for every document type (event invoice.cancelled). A cancelled credit note also records its invoice
  • Document duplicated, with the source document (event invoice.duplicated)
  • Credit note draft created from an invoice (event credit_note.issued)
  • Document deleted
  • Email accepted by the mail server (event email.accepted)
  • Email written to the mail log, with no email sent (event email.logged)
  • Email failed (event email.failed) or result unknown (event email.unknown), with severity Warning
  • Email not sent, for example with no recipient left (event email.cancelled)
  • Delivery recorded with Record delivery (event document.delivery_recorded)
  • Issued original missing or changed (events document.artifact_missing and document.artifact_changed)
  • Note added

The email events apply to document emails and reminders. They store the number of recipients and a hash of each address, not the addresses.

Payments

  • Payment recorded, for full and partial payments (event invoice.paid)
  • Payment reversed, with the amount, the payment date and the reason (event invoice.payment_reversed)
  • Refund recorded on a credit note (event credit_note.refunded)
  • Refund reversed, with the amount, the refund date and the reason (event credit_note.refund_reversed)

Reminders and recurring invoices

  • Reminder emails, automatic or manual, through the email events above
  • Recurring schedule created, updated, paused, resumed or deleted
  • Invoice generated from a recurring schedule

Customers, items and settings records

  • Customer created, updated or deleted; customers imported or exported
  • Item created, updated or deleted; items imported or exported
  • Item category created or updated
  • Tax rate created, updated, deleted or put in another order
  • Bank account created or updated
  • Company logo updated or removed
  • Invoices exported from the reports

Backups

  • Backup created, downloaded, deleted or restored
  • Backup settings updated

System

  • Application installed
  • Update installed
  • Update failed

Event details

Each event records:

Field Description
Event type What happened
Severity Info, Warning, or Critical
Actor The user who performed the action, or "System" for automated events
IP address The IP address of the request
User agent The browser or client that made the request
Request ID Unique identifier for matching related log entries
Timestamp When the event occurred
Metadata Context for the event type

Filtering

Filter the audit log by these fields, then click Filter. Click Clear filters to reset them.

The filters are:

  • Event type: one exact event. The list offers only events already in the log. The default is All events
  • Severity: Info, Warning, or Critical
  • Actor: events from a specific user
  • From date and To date: limit results to a time period
  • Search: free-text search across event names, IP addresses, and request IDs

Localization

You can use the audit log in all 13 languages. The event names are translated. The event codes and the metadata are not.

Need help with the product?

Contact support