Log inGet Vautir

Search the help center, features, guides and more.

The audit log

Read what happened in a Vautir organization, and send its audit log to a webhook, Splunk, Datadog, Microsoft Sentinel or S3.

Every organization has a log of what happened in it: who did it, when, and what. Owners and admins read it under Activity, in the console. Members don’t see it.

What’s in it

  • Sign-ins, with the address they came from, and whether your identity provider vouched for them.
  • Members invited, joined, removed, taken away by your identity provider, or given another role.
  • Groups made, renamed and deleted, and who’s in them.
  • Vaults made, and who has them.
  • Policies changed.
  • A member’s new device let in, or refused, by an admin.
  • Items saved or deleted in a vault: who, which vault, and how many.
  • Items opened, and items filled, in the organization’s vaults.
  • The plan, and where the log is sent.

Events are numbered 1, 2, 3 and so on, without gaps.

Items opened and filled

Our server can’t see you open an item: it’s already on your device. So the apps report it, with their next sync, for an organization’s vaults only. An app that’s offline reports late, with the time it noted. Nothing is reported for anyone’s own vaults.

Sending it on

On Business, an admin names one destination for the organization, in the console:

Destination You give
Webhook An https address and a secret. Each batch is signed with HMAC-SHA-256
Splunk The HTTP Event Collector’s address and token
Datadog Your Datadog site and an API key
Microsoft Sentinel A tenant, an app registration, a data collection endpoint, a rule and a stream
S3 A bucket, its region, and an access key

Events follow in batches, oldest first, starting from when the destination is set. A batch that fails is sent again, and the console shows the last error. Use a token that can only write logs.

What to know

  • Names stay with you. The log names people by email address, and groups, vaults and items by ID: their names are encrypted where we can’t read them. The console looks the names up on your own device; a log system gets the IDs.
  • It’s a record, not a lock. Our server writes the log, and a changed app could skip reporting an item it opened.
  • It’s kept as long as the organization is. A setting for how long comes later.

Last updated October 4, 2026