Activity log
The activity log records who did what on your account, when, and from which address. It covers every change to a setting and every access to something sensitive — a recording played, a transcript read, a bulk export taken — and it includes anything we do on your account, named.
Some entries say "Values withheld", and that is deliberate rather than a gap. The log's job is recording that a recording was played, by whom and when. It does not repeat the recording's address, the transcript's text, or the exact fields that left in an export — because a log that reproduced them would be a second copy of the thing it exists to police, and reading the log would become another way to reach the data. The field names are listed, so you can see what the entry covered without the entry becoming the leak.
Who can read it
The activity log needs its own permission, and only account administrators and agency owners hold it. That is on purpose and it is the one thing about this screen people query: a marketer who can change your forwarding number deliberately cannot read who changed it. The person whose actions are recorded should not be the person who audits them.
If your role cannot open it, the screen says so in as many words rather than reporting an error. Ask an administrator to grant it.
When we look at your account
Proofbell support can see your account's commercial state — your plan, your usage against it, call volumes and billing status — to answer a question or investigate a problem. Every one of those reads writes an entry into this log, with the member of staff's own email address on it and marked as Proofbell staff, so you can see that we looked and who did.
Our staff cannot see a call, a caller's number, a recording, a transcript or a deal value. That is not a policy we apply carefully — those permissions cannot be granted to a staff account at all, and a build that granted one would refuse to start. So the entries you see from us concern your plan and your volumes, never your customers' conversations.
Reading an entry
Five things can appear in the Who column and they mean different things, so they are shown differently rather than collapsed into one word:
- A person's email address — one of your logins, or one of your agency's.
- Proofbell staff — us, with the individual's address. See above.
- Automatic — nobody. A scheduled job, a retention sweep, or an incoming request from a connected platform. This matters: an automatic retention deletion and a person deleting something are very different events, and a log that called both "unknown" would be useless for the question you are asking.
- An address, marked as since deleted — the person who did it, whose login has been removed. The trail keeps their name. A log that forgets who did something once they leave the company is not an audit trail.
- "A user who no longer exists", with an id — their record has been erased entirely, so only the identifier survives. Still a person, still not "automatic".
Each entry also carries a sensitivity. Anything above internal is an access to something belonging to your customers, which is why those are the entries whose values are withheld — and also the entries most worth scanning for.
Agencies: the agency-level view
If you run client accounts, the log opens on the whole agency and names the client on every row. Some rows belong to no client — creating a client account is one — and those are labelled Agency-level. They appear nowhere else, so "who added this client" is a question only this view answers.
Switch to This client only to see one client's trail on its own. A client's own logins see exactly that: their own account's entries, never the agency's other clients and never the agency-level rows, which would tell them other clients exist.
Filters, and one thing they do not do
The Action and Who lists are built from what has actually happened, not from a fixed list — so a new kind of action appears in them automatically. Both are built from the last 90 days, which is worth knowing: something that last happened two years ago will not be in the dropdown. The date range is not limited that way, so use it to reach further back.
Choosing All recording actions matches every action beginning with recording.
— playback, download, deletion — which is usually the question rather than any one of them.
An empty table with filters set says so. "Nothing has been recorded" and "nothing matches these filters" are shown as different messages, because on an audit log the first reading is the dangerous one: somebody checking whether a recording was played must not be shown a blank page by a filter they had forgotten about and conclude that it was not.
Older entries
Load older entries adds a page below rather than replacing what you are reading, and entries written while you read cannot displace anything you have already seen. That is not a detail: paging by position rather than by time can repeat and skip rows on a log that is being written to, and a skipped row is the one thing this feature must never do.
What is not here
- Reading this log is not itself recorded. Every page you loaded would write an entry, and within a week the log would mostly be a record of people looking at the log — which buries the accesses it exists to expose. A read is not a change.
- There is no export or CSV download of the log yet, and it is not in the warehouse export. Ask us if you need a copy for an audit.
- There is no alert on an entry. Nothing emails you when a recording is played.
- Entries are kept indefinitely and there is no retention setting for them. They hold who and when rather than the contents of anything, which is why they are treated differently from recordings and transcripts.