Docs · COMPLIANCE
Append-only activity history
Enterprise plans record who changed what — SSO settings, roles, exports, and sensitive configuration — in an append-only log your compliance team can filter and export.
COMPLIANCEWhat gets recorded
- SSO and identity provider configuration changes
- Role and permission updates for workspace members
- Security settings modifications (MFA policy, session settings where applicable)
- Data exports initiated by admins
- Selected administrative actions defined in the product audit schema
Using the audit log
- Open Settings → Security → Audit (Enterprise admin role required)
- Filter by actor (user), event type, and date range
- Inspect event payload summaries — full secrets are never written to the log
- Export the filtered view to CSV for SOC reviews or quarterly access certifications
Retention and integrity
- Events are append-only — operators cannot edit or delete individual rows in the UI
- A background retention job purges events older than your configured policy window
- Default retention is documented in your Enterprise order; contact hello@mizualign.com to adjust
- Audit export itself generates a new audit event (export action recorded)
Compliance practices
- Review SSO and role changes weekly during rollout, monthly in steady state
- Pair CSV exports with your access review calendar (SOX, ISO, internal ITGC)
- We do not claim SOC 2 certification — audit log is a control you operate, not a certificate
- For DPA and subprocessors see /security and /dpa