---
id: KB-AD-004
url: https://app.codecontract.io/help/administration/what-to-look-for-in-the-activity-log
idioma: en
categoria: administracion
audiencia: administrador
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-AD-002, KB-TZ-003]
citadoPor: [KB-AD-015, KB-AD-016, KB-AD-019, KB-GL-014]
---

# What to look for in the activity log

_Ten minutes a month, and exactly what to look at._

**Responde a:** see who did what · platform audit log · who downloaded that document · detect improper access

The log records everything, which is why reading all of it is useless. What works is looking at four specific things, once a month.

## The four

- Accounts still active for people who have left.
- Bulk downloads: someone taking far more at once than their work requires.
- Access at times or from places that do not fit that person.
- Permission changes nobody remembers making.

| What you see | What it usually is | What to do |
| --- | --- | --- |
| 400 documents downloaded on a Friday | Someone preparing an audit… or leaving | Ask, without accusing |
| Access at 4am | Almost always a different time zone | Check who and from where |
| A permission widened for no reason | A change made in a hurry and never reverted | Review it and set it back |

> [!IMPORTANT]
> Finding something odd is not accusing anyone. The vast majority of what stands out has an ordinary explanation, and asking before concluding is what makes this habit sustainable in a small team.

## When to look properly

When someone leaves on bad terms, when there is a dispute, or when something does not add up. That is when the log stops being hygiene and becomes the thing that answers the question.

> [!WARNING]
> The log cannot be edited, and that is deliberate: a log an administrator could retouch would prove nothing.

**How long is it kept?**

According to your retention policy.

**Can it be exported?**

Yes, for an audit or for your adviser.

**Can non-administrators see it?**

No. It is sensitive information about the people on your team.

## Ejemplos

**An administrator reviews the log and finds two active accounts for people who left months ago.**

- Closes them
- Checks they were not used since

→ Ten minutes of review close two doors that had been open for half a year.

**The log is only looked at when there is a problem.**

- Reviews what matters regularly

→ The odd thing shows before the incident.

**Access appears at an unusual hour.**

- Checks with the person before raising the alarm

→ The anomaly is explained or acted on.

**Somebody downloads many documents at once.**

- Checks what and why

→ The movement is understood.

**An auditor asks for evidence of oversight.**

- Shows the reviews performed, with dates

→ Oversight is demonstrable.

**The log has too much noise to read.**

- Filters by what actually matters

→ The review is manageable.
