Reading the Permission Change Log

2 min read

Published August 28, 2026

Updated August 29, 2026

Opening the log

The log is one click from the permissions page.

  1. Go to Settings, then Roles & Permissions.
  2. Press Change log at the top right.
  3. Entries are newest first.

What an entry shows

Each entry is one save, so if you changed nine permissions and pressed Save once, that is one entry with nine lines rather than nine separate entries.

  • Who made the change, and what role they had at the time
  • Who or what it applied to: a whole role, or one named person
  • The exact date and time, and the address it came from
  • Every permission that moved, with its value before and after
  • A 'risk accepted' marker where a segregation of duties warning was accepted
  • Why it happened: changed by hand, a reset, a prerequisite turned on automatically, or cleared because someone's role changed

Why names stay readable

The log stores the names of the person who made the change and the person it applied to, rather than looking them up later. That means an entry still makes sense after someone has left the shop and their account is gone, which is the moment a log is usually most needed.

The log cannot be changed

There is no way to edit or delete an entry, from the screen or otherwise. That is what makes it worth trusting. It also means the log grows over time, which is normal and nothing to manage.

Tip

If you are reviewing access after an incident, start with the 'risk accepted' markers and any entry where a permission moved from off to on.