Cloud/Settings/Audit Log
Audit Log
The organization's security-relevant event trail: who did what, when, filterable by action and actor, one page that answers "what happened here?".
Audit Log is the organization's memory. The description: "Security-relevant events across the organization." Reading it requires org:audit:read, which is why some members never see this page at all.

Audit Log
Security-relevant events across the organization.
The mockup is the real trail. Type member into the action filter and watch the stream narrow.
The trail
Every entry is one event: when it happened, the action in dotted notation like member.invited, apikey.created or sso.updated, the actor who performed it, and the target it landed on. The stream covers the surfaces you have just read: members joining and changing roles, invitations, keys created and revoked, SSO edited, teams reshaped.
Filtering
Two filters sit above the stream: Action, which accepts dotted patterns (the placeholder teaches the shape: "Action (e.g. member.invited)"), and Actor ID, which narrows to one identity's trail. Together they answer the two questions an incident raises: what was done, and who did it. The list paginates with Load more rather than pretending everything fits on one screen.
Why this page exists
Governance without a record is a claim, not a control. This page is where the organization's security story is written down, by the system, with no way to edit it: the same events that the AI Governance reports aggregate for your connectors are recorded here for the organization itself. When the question is "who changed what, and when?", this is the page with the answer.
What comes next
That closes the Organization group. The sidebar continues with the Seller Profile group: how buyers see you on the Marketplace, and the payouts behind it.