The audit log is a running record of what people do in your Vista Social account: who changed a setting, who approved or deleted a post, who invited or removed a team member, who exported data, and when. You can read it in Vista Social, export it to CSV, and pull it into your own systems through the API, MCP or Ask Vista.
If you only have a minute, here's the short version:
- Every action your team takes is recorded, from the web app, the mobile app, the API, AI assistants connected over MCP, Ask Vista, Slack, Microsoft Teams and automations.
- Account owners and managers can read it, filter it, and open any entry to see exactly what changed.
- Export to CSV for auditors, or pull it over the API into a SIEM or data warehouse.
- Retention is set per account. The default is 12 months, and we can set a longer or shorter period to match your policy.
- It's an Enterprise feature and it's off by default. Nothing is recorded until your organization asks us to turn it on.
What an audit log means for your organization
As more people touch your social presence (marketing, regional teams, agencies, customer care, and now AI assistants), it gets harder to answer simple questions:
- Who changed the approval workflow last week?
- Who deleted this post, and was it approved first?
- What did a contractor have access to, and what did they do with it before we removed them?
- Did someone export our customer conversations?
- Was this reply sent by a person or by an automation?
The audit log answers these from a record your team can't edit, instead of from memory or a support ticket. In practice organizations use it to:
- Investigate incidents. When something goes wrong (a post goes out early, a profile is disconnected, a setting changes), you can see who did it, when, from where, and what the value was before.
- Review access. See what each person does in the account, and confirm that people who left the team stopped acting in it.
- Hold automation accountable. Actions taken by automations, agents and AI assistants are recorded and marked as automated, under the person who set them up.
- Work with agencies and clients. Agencies managing several brands can show clients who did what on their behalf.
- Answer auditors without a scramble. Export the period and people an auditor asks about in a few clicks.
How it relates to compliance
Most security and compliance frameworks expect an organization to keep a record of who did what in the systems that hold its data, to review that record, and to keep it for a set period. Common examples:
| Framework or requirement | What auditors usually look for |
|---|---|
| SOC 2 | Evidence that access to systems is logged and monitored, and that changes can be traced to a person. |
| ISO/IEC 27001 | Event logs that record user activity, kept and protected, and reviewed regularly. |
| HIPAA | Audit controls that record activity in systems that handle protected health information. |
| GDPR | The ability to show who accessed or exported personal data, as part of accountability. |
| Financial services and pharmaceutical rules | A record of who drafted, edited, approved and published regulated communications, kept for a defined period. |
The audit log gives you that record for Vista Social: the person, the time, the action, what it acted on, how it arrived, whether it worked, and for sensitive changes the value before and after.
Note: The audit log is one part of a compliance program, not the whole of it. Your compliance team decides which records you need and for how long, and Vista Social provides the record, the export and the API to support it.
Availability: an Enterprise feature, off by default
The audit log is available on Enterprise plans. It is off by default, and nothing about your team's activity is recorded until your organization opts in. Some organizations want a detailed activity record; others would rather not keep one. The choice is yours.
To turn it on, contact your Vista Social account manager or our support team. Once it's on:
- Recording starts within a minute. There is no history from before it was turned on.
- Your retention period is set at the same time (see Retention below).
- If the feature is later turned off, recording stops and the audit log is hidden. Entries already recorded are not deleted early; they expire on their normal schedule, so turning the feature back on shows whatever hasn't expired yet.
What gets recorded
The audit log records every change made in your account, plus sign-ins, exports and downloads. That covers, among others:
| Area | Examples |
|---|---|
| Security and sign-in | Signing in and out, two-factor verification, password changes, API keys created or revoked, connected apps approved or disconnected, single sign-on settings |
| Team | Team members invited, updated or removed, role and permission changes, user groups |
| Profiles and profile groups | Social profiles connected, disconnected or moved, profile groups created, renamed or deleted |
| Publishing | Posts created, edited, approved, rejected, rescheduled, retried, deleted or imported in bulk, approval workflows |
| Inbox | Actions on messages and comments, inbox automations, macros and rules |
| Ask Vista and AI | Questions asked, chats, skills and agents created or changed, agent runs, AI images and videos, MCP connections |
| Settings | Account and profile group settings, time zones, compliance settings, white label, Slack and Microsoft Teams |
| Exports and downloads | CSV and calendar exports, report downloads, media downloads, audit log exports |
New parts of Vista Social are covered as they're built: every change made through the app or the API is recorded, even before we've given it a hand-written description.
What each entry contains
| Field | What it tells you |
|---|---|
| Time | When it happened, shown in the timezone you choose |
| Team member | Who did it, with their role at the time |
| Action | A plain description, for example "Approved 3 posts" or "Updated account settings: changed time zone from Europe/London to America/Chicago" |
| Target | What it acted on, for example a post, a profile group or a team member |
| Profile group | The profile group involved, when there is one |
| How it arrived | Web, mobile app, API, integrations such as Zapier and Make, MCP client, Ask Vista, Slack, Microsoft Teams or automation |
| Result | Whether it succeeded, and the error if it didn't |
| Changes | Before and after values for team member, permission, account and single sign-on changes |
| Request | The IP address, browser or app, and the details sent with the request |
What is not recorded
- Browsing and reading. Opening the calendar, viewing a report or reading messages isn't recorded. Exports, downloads and viewing the audit log itself are.
- People who aren't signed in. Failed sign-in attempts, reviewers approving through emailed links and visitors to your Vista Pages aren't part of the log.
-
Secrets. Passwords, tokens, one-time codes and keys are replaced with
[redacted]before anything is stored. Uploaded files are recorded by name, size and type, never their contents.
Automations and AI assistants
When an inbox automation, a scheduled Ask Vista agent or an AI assistant connected over MCP takes an action, the entry is recorded under the person who set it up and marked as automated, with the automation or agent named. You can always tell whether a person or an automation did something.
Vista Social support
When our support team works inside your account to help you, that access is recorded in our own internal audit trail and governed by our security policies.
Who can see the audit log
The account owner and managers can open the audit log, see the Activity tab on team members, export it and read it over the API and MCP. Other team members can't, whatever their permissions in profile groups. The audit log covers the whole account, so access isn't split by profile group.
Viewing and exporting the audit log are recorded too, so you can see who looked at it.
Using the audit log
Opening it
- Go to Settings > Team Members.
- Click the three-dot menu at the top of the page.
- Choose Audit log.
Entries are grouped by day, newest first, one line each: the time, the team member, the action and how it arrived. A ×5 next to an action means the same thing happened several times in a row and was grouped into one entry. A red Failed badge means the action didn't go through.
Finding what you need
- Search matches the action, the names of things acted on and team member emails.
- Timezone sets the timezone for every time on the page, the date range and the export. It starts as your computer's timezone, and your choice is remembered in this browser.
- Date range offers quick picks (last 7 days, last 4 weeks, last 3 months, month, quarter or year to date) or any custom range.
- Select filters narrows the list by team member, area, profile group, how it arrived (web, mobile app, API, MCP client, Ask Vista, Slack, Microsoft Teams, automation) and whether it succeeded or failed.
Reading an entry
Click the arrow at the end of a row to open the details panel. It shows the full date and time with the timezone, the team member, the area, the target, the profile group, how it arrived, the result, any before and after changes, and the request: the IP address, the browser or app, and the details that were sent.
Click a team member's name to open their team member page.
Activity for one team member
Every team member page has an Activity tab with the same list, filtered to that person. Use it for access reviews or when someone leaves the team.
Exporting to CSV
Click Export CSV at the top of the audit log. The file contains every entry that matches your current search, date range and filters, with no row limit.
Each row includes:
- The date and time in your chosen timezone, and again in UTC
- The team member's name, email and role
- The action, its category and its key
- The target, its type and ID, and the profile group ID
- How it arrived, and the automation if one was involved
- The result and any error
- The before and after changes
- How many times it repeated
- The IP address and the request
The file opens directly in Excel, Google Sheets and Numbers. Cells that start with characters a spreadsheet would treat as a formula are written as text, so a file can't run anything when it's opened.
API access
The audit log is available through the Vista Social REST API, so you can pull it on a schedule into a SIEM, a data warehouse such as Snowflake or BigQuery, or long-term archival storage.
POST https://api.vistasocial.com/v2/audit-log/list
x-api-key: YOUR_API_KEY
Content-Type: application/json
{
"from_date": "2026-10-01",
"to_date": "2026-10-07",
"timezone": "America/New_York",
"limit": 200
}| Parameter | What it does |
|---|---|
timezone |
Your IANA timezone, for example America/New_York. Dates without a time cover the whole day in this timezone, and each entry includes its time in it. Defaults to UTC. |
from_date, to_date
|
A date (2026-10-01) or a full ISO 8601 time with an offset |
actor_user_gid |
Only entries by one team member |
category |
Only one area, for example security, team, publishing or export
|
action |
Only one action key, for example team.member.remove
|
profile_group_id |
Only entries in one profile group |
surface |
Only entries that arrived one way: web, mobile, api, mcp, ask_vista, slack, teams or automation
|
ok |
true for successful actions only, false for failed ones only |
q |
Free text search |
limit |
Entries per page, 1 to 200, default 25 |
cursor |
The next_cursor from the previous page |
include_request |
Include the IP address, browser and request details on each entry |
The response lists entries newest first. Each entry has created_at in UTC and created_at_local in your timezone. To read everything in a range, keep calling with the next_cursor you get back until has_more is false.
{
"ok": true,
"data": {
"results": [
{
"created_at": "2026-10-06T14:56:32.000Z",
"created_at_local": "2026-10-06T10:56:32-04:00",
"actor": { "kind": "user", "name": "Jane Smith", "email": "jane@example.com", "role": "manager" },
"action": "team.member.remove",
"category": "team",
"summary": "Removed alex@example.com from profile groups",
"via": { "surface": "web" },
"result": { "ok": true }
}
],
"next_cursor": "MTc5MTI5...",
"has_more": true,
"timezone": "America/New_York"
}
}The API key must belong to the account owner or a manager. If the audit log isn't turned on for the account, or the key belongs to someone else, the API answers 403 with feature_disabled or forbidden. Audit log calls count toward your normal API rate limits.
Tip: For records you must keep longer than your retention period, run a daily job that pulls the previous day with
from_dateandto_dateand stores it in your own archive.
MCP and Ask Vista
The audit log is also available to AI assistants. Ask Vista and any assistant connected to Vista Social over MCP (ChatGPT, Claude, Cursor and others) can read it through the listAuditLog tool, with the same filters as the API. See Connect your AI assistant to Vista Social (MCP).
That means owners and managers can simply ask:
- "What has Mike been doing lately?"
- "Who changed our approval workflow last week?"
- "Which actions failed this month?"
- "Did anyone export data in September?"
The same rule applies: the assistant only answers for the account owner and managers, and only when the audit log is turned on. It tells anyone else plainly that they don't have access. Times are given in your timezone.
Retention
Entries are kept for a set period and then deleted automatically.
- The default is 12 months.
- Retention is configured for each customer. If your policy calls for a longer period (for example 3, 5 or 7 years) or a shorter one, ask your account manager or our support team and we'll set it for your account.
- A change applies to entries you already have. Lengthening the period keeps existing entries for longer. Shortening it deletes entries older than the new period, so we'll confirm with you first.
- To keep records longer than your retention period, export them to CSV or pull them over the API into your own archive.
Frequently asked questions
Can anyone edit or delete audit log entries? No. There is no way to edit or delete entries in Vista Social. They are removed only when they reach the end of your retention period.
Can I see what happened before the audit log was turned on? No. Recording starts when the feature is turned on.
Does the audit log slow anything down? No. Entries are written after each action completes, and your team won't notice any difference.
Why are some actions described in more general terms than others? Every change is recorded, including in parts of Vista Social we haven't written a detailed description for yet. Those entries get a general description, such as "Updated publishing settings", and the details panel always shows exactly what was sent.
Why do some entries show a "×" number? When the same person does the same thing several times in quick succession, for example opening the audit log repeatedly, the entries are grouped into one with a count, so the log stays readable.
How do I turn it on? Contact your Vista Social account manager or our support team. The audit log is an Enterprise feature and is off until your organization opts in.