Audit log
Append-only. Includes all seat, module, licence and provisioning changes. UPDATE, DELETE and TRUNCATE are revoked from every role, including SuperAdmin.
Access to tenant data
Three routes in, each leaving a record here and on the organisation's own screen: an impersonation session (time-boxed, reason-bound, read-only by default), a data-access consent the tenant grants and can revoke, and a support break-glass grant scoped to one module and one record. There is no fourth.
| Time | Actor | Action | Tenant | Detail |
|---|