Audit Logs & Security
View comprehensive audit logs of every action in your Muin organization — who did what, when, and what changed. Essential for compliance and security.
Muin maintains comprehensive audit logs of all activity in your organization. Essential for security monitoring, compliance requirements, and investigating issues.
Audit Logging Overview
Muin logs all significant actions:
- Who performed the action
- What action was taken
- When it occurred
- Where (IP address, device)
- What changed (before/after values)
What’s Logged
User Actions
| Action Type | Examples |
|---|---|
| Authentication | Login, logout, password change |
| Document | Upload, view, edit, delete, download |
| Data | Create, update, delete records |
| Approval | Approve, reject, delegate |
| Settings | Configuration changes |
| Team | Invite, remove, role change |
System Events
| Event Type | Examples |
|---|---|
| Processing | Document processed, extraction complete |
| Workflow | Workflow triggered, action executed |
| Agent | Agent run started, completed, failed |
| Integration | Sync started, API call, webhook |
Security Events
| Event Type | Examples |
|---|---|
| Access | Failed login, suspicious activity |
| Permissions | Access denied, role changed |
| Data | Sensitive data accessed, exported |
Viewing Audit Logs
Accessing Logs
- Navigate to Settings → Security → Audit Logs
- View recent activity
- Use filters to narrow results
Log Entry Details
Each entry shows:
- Timestamp - When it occurred
- User - Who performed action
- Action - What was done
- Resource - What was affected
- Details - Additional context
- IP Address - Where request originated
Example Entry
2026-01-15 14:32:17 UTC
User: jane.smith@company.com
Action: Document Approved
Resource: Invoice #INV-2024-0892
Details: Approval for payment, amount $4,567.00
IP: 192.168.1.100
Session: Browser, Chrome on macOS
Filtering and Search
Filter Options
| Filter | Options |
|---|---|
| Date Range | Custom range, presets |
| User | Specific user, all users |
| Action Type | Authentication, document, etc. |
| Resource Type | Documents, users, settings |
| Status | Success, failure |
Search
Search logs by:
- User email
- Resource name or ID
- Action keyword
- IP address
Saved Filters
Save frequently used filters:
- Configure your filters
- Click Save Filter
- Name your filter
- Access later from saved filters
Audit Reports
Standard Reports
| Report | Contents |
|---|---|
| User Activity | All actions by specific user |
| Document Access | Who accessed what documents |
| Login History | Authentication events |
| Configuration Changes | Settings modifications |
| Approval History | All approval actions |
Running Reports
- Navigate to Audit Logs → Reports
- Select report type
- Set date range and filters
- Generate report
- Export as PDF or CSV
Scheduled Reports
Automate compliance reporting:
- Configure report parameters
- Set schedule (daily, weekly, monthly)
- Add email recipients
- Reports delivered automatically
Export for Compliance
Export Formats
| Format | Use Case |
|---|---|
| CSV | Analysis in spreadsheets |
| JSON | Integration with SIEM |
| Documentation and audits |
Bulk Export
For large exports:
- Set date range and filters
- Click Export All
- Choose format
- Export runs in background
- Download when ready
Compliance Packages
Generate audit packages for:
- SOC 2 audits
- GDPR requests
- Internal audits
- Security reviews
Retention Policy
Default Retention
- Standard activity: 1 year
- Security events: 2 years
- Compliance-related: 7 years
Configuring Retention
Enterprise customers can configure:
- Navigate to Settings → Security → Data Retention
- Set retention period by log type
- Configure archive policy
- Set deletion policy
Archive Access
Archived logs:
- Moved to cold storage after active period
- Accessible via special request
- May take longer to retrieve
- Full fidelity maintained
Security Monitoring
Real-Time Alerts
Set up alerts for security events:
- Navigate to Settings → Security → Alerts
- Configure alert rules:
- Failed login attempts (>3)
- Login from new location
- Sensitive data export
- Permission changes
- Set notification method
- Enable alerts
Suspicious Activity
Muin flags potentially suspicious activity:
- Multiple failed logins
- Unusual access patterns
- Large data exports
- Access from blocked locations
Responding to Alerts
When alerted:
- Review the activity
- Check if legitimate
- Take action if needed:
- Reset password
- Disable account
- Investigate further
Access Control for Logs
Who Can View Logs
| Role | Access |
|---|---|
| Owner | All logs |
| Admin | All logs except billing |
| Manager | Logs for their team only |
| Member | Their own activity only |
Protecting Audit Integrity
- Logs cannot be modified or deleted by users
- Log system isolated from main application
- Configurable retention policies per log type
Best Practices
For Security
- Review regularly - Check logs at least weekly
- Set up alerts - Don’t rely on manual review
- Investigate anomalies - Don’t ignore unusual activity
- Limit access - Only necessary people view logs
For Compliance
- Know requirements - Understand what you need to log
- Set retention appropriately - Meet regulatory minimums
- Regular exports - Don’t rely only on Muin storage
- Test retrieval - Ensure you can get logs when needed
For Troubleshooting
- Correlate events - Look at related entries
- Check timestamps - Understand sequence of events
- Look at context - Before and after the issue
- Export for deep analysis - Use external tools if needed
Troubleshooting
Can’t Find Expected Log Entry
- Verify the action actually occurred
- Check your date range filter
- Try broader filters first
- Check if action type is logged
- Allow for slight timestamp differences
Log Export Issues
- Reduce date range for large exports
- Try different export format
- Check export isn’t still processing
- Contact support for very large exports
Access Denied to Logs
- Verify your role has log access
- Check with admin for permissions
- Some logs may be restricted by role
Next Steps
- Security Settings - Configure security
- Team Management - Manage access