Skip to content
Esc
navigateopen⌘Jpreview
On this page

Review account activity and changes

Find who accessed a record or changed a setting, using the Activity and Audit lenses and their searchable history window.

When a setting changed and no one remembers changing it, or you need to show who reached a record, open Records > Activity. The page carries two lenses over the same phone system: Activity answers who accessed what, and Audit answers what changed. Start from the question you are actually asking — the two lenses hold different columns and different amounts of history.

Prerequisites

  • The intended phone system selected in the header.
  • Activity-log read access, audit-log read access, or both. The page only offers the lenses your account can view, and the navigation entry is hidden without at least one of them.
  • Listing API keys by name additionally needs user read access. Without it the API key selectors fall back to All API keys.

Choose a lens

Lens Answers Columns
Activity Who accessed what, and was it allowed When and request identifier, principal, the access evaluated with its method and route, the decision, the HTTP status, and the source IP address.
Audit What changed When, principal, the resource type and identifier, the action, and the source IP address. Rows with recorded detail expand to show it.

In the Activity lens the Decision column reads Allowed, Denied, or No Decision, and a denied row adds the reason underneath. A denied row is the record of an attempt that was refused, not a record of a change.

In the Audit lens the Action column reads Created, Read, Updated, or Deleted. Reads of sensitive media are deliberately recorded here too — playing or downloading a call recording appears as a Call Recording read, and voicemail audio as a Voicemail Audio read.

Narrow the results

  1. Open Records > Activity and pick the lens.
  2. Set the time window at the bottom of the filter panel. The window is shared by both lenses and defaults to the last seven days. Boundaries follow the phone system’s configured time zone, and a fallback is labelled when that time zone is missing or invalid.
  3. Filter the Activity lens by actor identifier, API key, resource, action type, authorization outcome, or HTTP status.
  4. Filter the Audit lens by actor identifier, API key, resource type, or change type.
  5. On the Activity lens, select Include log-viewing requests when you want the requests that read these logs to appear as well. They are excluded by default so reviewing the ledger does not bury what you came to find.
  6. Select a principal shown as an API key to open that key’s own history, including activity from keys it replaced during rotation.

Resource and resource-type filters are pick-lists rather than free text, so a filter that returns nothing means no matching rows, not a typo.

Understand the history window

Above the results, a notice states how many days of searchable live history the lens holds and the date that history begins. Activity access records and audit change records keep different windows: audit history reaches back much further than activity history. Read the number in the notice rather than assuming one.

If your selected range starts before that date, the notice adds a Range crosses archive boundary badge. Records older than the live window are retained in a secure archive and are not returned in this view. Narrow the range to the live window for a complete answer, or contact support when you need something older.

Understand what is shown and what is masked

  • Work performed by Steer staff appears as Steer staff rather than a named person, and the source IP address, browser details, and internal handles are removed from those rows.
  • An Origin column and filter appear only when your phone system is set up to expose Steer Phones platform records. When they are absent, every row you can see is your own organization’s.
  • A principal with no resolvable name is shown as Unknown actor.

Expected result

You can name the principal, the exact time, and the resource involved — and, in the Audit lens, expand the row to see the recorded detail of the change. That is enough to answer an internal question or to hand to support.

Troubleshooting

  • The Activity entry is missing from the navigation: Your role does not include either log permission for this phone system. Ask an administrator to review your access.
  • Only one lens button is shown: You can view that lens only. The other is not hidden data; it is a separate permission.
  • A change you expected is absent: Widen the time window first, then check the archive-boundary badge, then clear the resource-type filter. A change made by an integration appears under its API key, not under a person.
  • A row shows a denied decision: Someone or something attempted access that was refused. Nothing changed. Use the reason and the source IP address to identify the caller.
  • A row’s principal reads Steer staff: Steer Phones performed the action. The identity behind it is masked by design; contact support with the timestamp if you need context.
  • The results look inconsistent between visits: Confirm the selected phone system and that the time window is the one you set — the window persists across the lens switch.