A CRM audit log that settles who changed what, and when
The CRM audit log in DigiPix Flow records what happens in your workspace as it happens: who changed a lead's owner, who moved a deal, who signed in or failed to, and who exported the contact list, with the value before and after each change. Entries are only ever added, never edited or removed, so when a number is questioned you open the log rather than start an argument.
- Every change kept with its before and after values
- Search and filter by person, record, category and date
- Exports recorded, with a reason when you require one
- categories, from leads and deals to security
- 8
- the longest window in the main log
- 2 yrs
- minimum for security and sign-in events
- 7 yrs
What the audit log records
- Leads and dealsOwner changes, status moves and stage changes
- Users and rolesInvites, role changes and permission edits
- Sign-insSuccessful and failed attempts, and lockouts
- Imports and exportsWho took data in or out, and when
- FilesUploads and file activity on records
- SettingsWorkspace configuration and automation changes
A deal value nobody admits to changing
On Monday the pipeline review shows a ₹6 lakh deal at Negotiation. By Friday it reads ₹4 lakh with a different owner, and three people swear they never touched it. Without a record of the change, the meeting becomes a debate about memory instead of a decision about the deal.
A contact list that walked out of the door
A sales executive resigns, and a week later a competitor seems to know your best accounts. Did anyone download the contact list before leaving? Without an entry for every export, nobody can say, and nobody can show a customer what was done with their details.
An auditor who wants evidence, not screenshots
A client's procurement team, an investor or your own accountant asks who can see customer data and what changed last quarter. Pulling the answer together from chat messages and memory takes days, and still does not prove anything.
Each change written down with who did it and what it was before
Changes to leads and deals, user and role changes, sign-ins, imports, exports, files and workspace settings are each written to the log as they happen. An entry names who acted: a person, an API client or the system itself. If a support user ever works in your workspace as one of your people, the entry names both. Opening an event shows the value before and after the change, and every entry says plainly that it cannot be edited or deleted.
- Before and after values on the change
- People, API clients and system actions told apart
- Both names shown when support acts as a user
- Entries that cannot be edited or deleted
Go straight to the one change you are looking for
Search across events, people and records, then narrow the list by category, by the person who acted and by date: the last 7, 30, 90 or 365 days, or a range you pick. Turn off system activity when you only care about what people did. Separate views gather security events, and exports and access, so the questions asked most often have their own page.
- Search events, people and records
- Filters for category, person and date range
- System activity hidden with one switch
- Views for security, and for exports and access
A lead's own history, and a person's own activity
The same trail appears where you need it. A lead's History tab lists the changes made to that lead, so a rep can see who reassigned it before calling the buyer. A user's page shows what that person has done in the workspace, which is the first place a manager looks when someone moves on. Both read from the same append-only log, so they always agree with it.
- A History tab on each lead
- An activity panel on each user's page
- Owner and status changes visible to the team
- One trail behind every view
Export to CSV, and leave a record of the export itself
Download the events in your current view as a CSV file for an auditor or a customer's review. Exporting is a permission of its own, separate from viewing the log. Admins can require a reason before any export starts, and the server checks it. Each export is then written to the log with the person, the number of rows and the reason. Exports are blocked while a support user is working in your workspace.
- CSV of exactly the view you filtered
- Export held as its own permission
- A required reason, checked by the server
- Every export recorded with its row count
Hear about failed sign-ins and data exports without opening the log
Switch on alerts and the workspace's owners and admins are told, in the app and by email, when someone enters a wrong password for a real account, when an account is locked, and when someone requests or downloads a data export. Failed sign-ins are announced at most once an hour per person, so one forgetful colleague does not fill your inbox, and up to ten admins receive each alert.
- Failed sign-ins and account lockouts
- Data exports requested or downloaded
- In-app and email, to owners and admins
- One failed sign-in alert an hour per person
Keep the log as long as you need, and never lose an entry
Choose how long events stay in the main log: 90 days, 180 days, a year or two years. Each night, older events move to a cold archive, which never deletes them. Security and sign-in events are kept for at least seven years whatever window you pick, and anything under a legal hold is never archived. Changing these settings is recorded in the log too.
- Windows of 90, 180, 365 or 730 days
- Older events archived each night, not deleted
- Security and sign-in events kept seven years
- Legal holds never archived
Setting up the audit log, in five steps
- STEP 01
Decide who may look
Give viewing, opening an event's detail and exporting to the roles that need each one.
- STEP 02
Set the rules
Require a reason for exports, choose the retention window and pick the list's defaults.
- STEP 03
Turn on alerts
Let owners and admins hear about failed sign-ins, lockouts and data exports.
- STEP 04
Find the change
Search and filter by person, record, category and date when a question comes up.
- STEP 05
Export the evidence
Download the filtered view as CSV, with the export itself recorded in the log.
The audit log vs spreadsheets and shared logins
| What it covers | Spreadsheets and shared logins | |
|---|---|---|
| Who changed a record | Whoever last had the file open | The person, API client or system named on the entry |
| What it was before | Lost when the cell was overwritten | Before and after values on every change |
| Editing the history | Anyone can change any row | Entries can only be added, never edited |
| Data leaving the business | A copy emailed with no trace | Every export recorded, with an alert to admins |
| Failed sign-ins | A shared password nobody tracks | Recorded, with alerts on failures and lockouts |
| An auditor's request | Screenshots stitched together over days | A filtered CSV, downloaded from the log |
| How long it is kept | Until someone deletes the file | A window you choose, then archived, not deleted |
Activity from connected systems, recorded too
Changes made through the API are recorded with the API client that made them, so a connected system is never anonymous, and imports are logged alongside the exports they balance.
Audit log questions, answered
What is a CRM audit log?
It is a dated record of what people and systems did in your CRM: who created or changed a record, what the value was before and after, who signed in, and who exported data. In DigiPix Flow the log is append-only, so entries are added as things happen and can never be edited or removed afterwards.
What does the DigiPix Flow audit log record?
Changes to leads and deals, user, role and permission changes, sign-ins and failed sign-ins, imports and exports, file activity and workspace settings. Each entry carries the time, the actor and a written summary, and opening it shows the value before and after the change.
Can anyone edit or delete an audit entry?
No, not even a workspace owner. There is no edit or delete action for audit entries. When older events pass your retention window they move to a cold archive each night, which keeps them rather than deleting them, and security and sign-in events stay for at least seven years.
Who in my team can see the audit log?
Only roles you give it to. Viewing the log, opening an event's full detail and exporting are three separate permissions, so a manager can review activity without being able to download it. Opening an event's detail is itself recorded in the log.
Can I see the history of a single lead?
Yes. Each lead has a History tab built from the same audit log, listing the changes made to that lead, such as owner and status changes, with who made them and when. A user's page shows that person's own activity in the same way.
How do I export the audit log for an auditor?
Filter the log to the period and events the auditor asked for, then export the view as a CSV file of up to 10,000 events. If your admins require a reason, you enter it before the download starts. The export is recorded in the log with your name, the row count and the reason.
Will I know if someone exports our data?
If export alerts are on, the workspace's owners and admins are told in the app and by email when someone requests or downloads a data export. The person exporting is not alerted about their own export, and every export is in the log whether alerts are on or not.
What happens when DigiPix Flow support works in our workspace?
Anything a support user does while acting as one of your people is recorded with both names, so you can tell their actions apart from your colleague's own. Audit exports are blocked for the whole of that support session.
Something we haven't covered? Talk to an expert
Keep reading
Visit the blog- FEATURESCRM security and accessMFA on every plan, roles with data scope and IP restrictions.Explore the feature
- FEATURESPlatform and admin controlsUsers, teams, roles and workspace settings in one place.Explore features
- FEATURESImport and exportBring records in, take them out, and see every job's result.Explore the feature
- FEATURESConsent and opt-outsEach person's channel consent recorded with when it was given.Explore the feature
- INTEGRATIONSCRM file storageWhere attachments are stored, how each file is scanned, and who can download it.See the integration
ARTICLEYour best salesperson's WhatsApp is your biggest riskWhy customer conversations belong on the record, not on one phone.Read the article
GUIDEDPDP Act for Marketing: A Practical Checklist for Indian Sales and Marketing TeamsWhat the DPDP Act for marketing and sales teams means in plain language: the key terms, notice and consent, withdrawal, security, breaches, children's data and people's rights, with a checklist for handling leads. General information from the official texts, not legal advice.Read the guide
Know who changed what, every time
Talk to an expert. Bring the question your auditor or your team asked last, and see the log answer it.
- A real person, not a bot
- Bring a real audit question
- See the answer in the log







