What it records
The audit log answers two questions that come up when several people share an account:
"Who signed off on this post?" Every review event: a review requested, approved, sent back, the post edited after review, a review reset.
"Who gave this person that access?" Every membership change: an invitation, a role change, a capability granted or removed.
Find it at Settings โ Audit log. Admin only.
Reading it
Two tabs, one per category โ Reviews and Permissions. Each entry shows who did it, what they did, which post or person it was about, and when.
Filter by event type and by date range. Results are newest first, fifty to a page.
Exporting
Export CSV downloads the current view โ the same filters you have applied, without the pagination. That is the format to hand to whoever is asking, whether that is a client, an auditor, or a security questionnaire.
Exports are capped at 50,000 rows. If your range is bigger than that, narrow the dates and export in pieces.
What it is not
It is not a full activity feed. It does not record every post created, every draft edited, or every login. It records the two categories above, which are the ones people actually need to reconstruct โ approvals and access.
If you need something logged that is not there, tell us what and why.
Retention
Entries are kept for the life of the account. Nothing is trimmed on a schedule.
Deleting a post does not delete its review history โ that is the point of an audit log.
Availability
Available on every plan, but only useful once more than one person is in the account. Approvals themselves start at Business, so on Pro the Reviews tab will be empty.