The audit log
What the audit log records on its Organisation and Authentication tabs, who can see it, and how long quickS3 keeps events before they go.
The Audit log page shows what happened in your organisation over the last 14 days: who uploaded, downloaded, or deleted which file, who changed a role, who signed in, and whether each attempt was allowed. Owners and Admins can see it. Members can’t.
It has two tabs:
- Organisation: file actions (listing, downloading, uploading, deleting), share links, AI client activity, and changes to people, roles, and connections.
- Authentication: sign-in link requests, successful and failed sign-ins, sign-outs, and accepted invitations, with the IP address they came from.
The page opens on the last seven days, newest first, 100 events at a time. Select Load more events at the bottom to go further back.
Reading an event
Each row shows the time, the person, what they did, what it was done to, and the result:
- Allowed (green) or Denied (red) on the Organisation tab. A denied row means quickS3 refused the action, for example because no role allowed it.
- Success or Failed on the Authentication tab.
Select a row to see everything recorded about it, like the full file path, the user ID, and extra details such as which AI client or share link was involved.
Two kinds of row are worth knowing:
- Download via share link is someone opening a public link. It’s listed under the person who created the link, because the download runs on their access, but it wasn’t them downloading.
- AI access granted, AI access revoked, and file actions carrying an AI client in their details come from AI clients people have connected.
What it’s good for
- Checking that a new role works: ask the person to try, then look for their Allowed and Denied rows.
- Answering “who deleted this file?” within the last two weeks.
- Spotting failed sign-ins or unexpected downloads.
What it isn’t
Events are deleted after 14 days. If you need to keep something longer, export it before then.
The audit log is a record of activity for your team to review, not a tamper-proof archive for compliance. If you need that, also switch on your storage provider’s own logging.