Settings > Security > Audit log. Filterable by actor, action, and date range. CSV and JSON export.
What is logged
Logins (success and failure), permission changes, settings edits, integration installs and disconnects, data exports, agent invites, AI override actions, refund actions, plan changes.
SIEM forwarding
On Enterprise, audit events forward to your SIEM (Splunk, Datadog, Sumo Logic) in near real time over the standard syslog or webhook channels.