The change log
Every change to a role or a permission is logged with timestamp, the user who made the change, and before/after values.
Why the log exists
- Audit — you can always prove who granted or revoked which permission, and when.
- Forensics — after a security incident the log shows whether someone modified a permission outside normal hours.
Where to find the log
Under Roles & permissions, open the Change log tab. The latest 100 entries are shown by default, newest first. You can filter by user, role, or permission.
What an entry contains
- When — date and time, to the second.
- Who — the employee who made the change (name, role).
- What — the affected role and the permissions that changed.
- Before / after — which ticks were set, which are set now.
Recommendation
Review the log periodically, not only after an incident. Watch for unusual patterns: changes outside business hours, many changes in rapid succession, or an employee granting themselves new permissions.