A per-write append-only trail behind the team directory. It records from-role, to-role, from-status, to-status, the reason and who did it, and it is deliberately best-effort so that a logging failure can never block the access change itself.
Also called: access audit · who granted admin · revocation record · permission history
- 1Every write in the staff route calls the audit helper before returning.
- 2Revocation refuses to proceed without a reason string.
- 3The trail renders under the roster behind a 'Show history' toggle.
- 4The audit write never fails the operation it describes.
Same root cause as the directory: an env var drifted and a sub-account owner held administrative access to every other customer for weeks, with nothing on record to notice it by. The route's header states the rule plainly: 'EVERY WRITE IS AUDITED — Invite, role change, revoke, reinstate.'
- Role changes left no trace, so an unexpected permission had no explanation.
- Revocations without a reason are re-litigated later with nobody able to say why.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →