---
title: "See what was done in your practice in the audit log"
summary: "Open the audit log in your organization settings, filter it to one person or connected system, and export what it shows as a CSV."
source: https://practor.app/en-za/help/security-and-integrations/see-everything-done-in-your-practice-in-the-audit-log
published: 2026-09-29T07:17:43.892Z
updated: 2026-09-29T07:17:43.892Z
category: "Security and integrations"
---

Practor keeps a record of the sensitive things done in your practice: a patient record opened, a sign-in, a permission changed, every request a connected system makes. The audit log is where you read those records.

Only practice owners can open it. Anyone else who opens it is told to ask a practice owner.

## Open the audit log

1. Go to **Organization settings**.
2. Open **Audit log**, under **Security & integrations**.

The newest events are at the top. The first line of a row says what happened. Under it are who did it and when, in your practice's time zone. A row that touched patient information has a **Patient data** badge, and one that didn't succeed shows its outcome.

## Filter to what you're looking for

Choose from the filters above the list. Each one narrows the list straight away.

| Filter | What it narrows to |
| --- | --- |
| **Show** | A kind of event: integration requests, integration changes, patient records opened, sign-ins and security, or exports |
| **By** | One person in your practice, or one connected system |
| **Outcome** | Events that succeeded, were rejected as invalid, were refused, or failed on our side |
| **From** and **To** | A range of days, in your practice's time zone |
| **Patient data only** | Events that touched patient information |

## Follow what a connected system did

1. Under **By**, pick the system. Connected systems are listed under **Integrations**, below the people in your practice.
2. Under **Show**, pick **Integration requests**.

Every request the system made is listed, including the ones Practor turned away. A request that read or changed a patient names that patient in its detail. Press the name to open their chart.

To see who changed the system's permissions, keys or webhooks, pick **Integration changes** under **Show** instead, and leave **By** on **Anyone**.

## Read the detail of an event

Press a row to open it.

![The audit log filtered to one connected system, with a request opened](https://res.cloudinary.com/drmnydbcs/image/upload/c_limit,w_1600/f_auto,q_auto:good/v1/help/integrations/audit-log.png?_a=BAMAOGDh0#848x603 "A request that registered a patient, with the patient named and linked.")

| What you'll see | What it tells you |
| --- | --- |
| Outcome and Reason | Whether it worked and, if not, why it was stopped |
| Request | For a connected system's request, what it called, like POST patients |
| Detail | What kind of change it was, such as **Key created** |
| Records | The records it touched, by type and id |
| Patients | The patients those records belong to. A patient your practice no longer holds a chart for shows as an id |
| Address | Where the request came from |
| Request id | The number to quote if you contact us about a request |
| Event id | The number of this entry in the audit log |
| Before and After | What a settings change was, and what it became |

An event has one of four outcomes.

| Outcome | What it means |
| --- | --- |
| Succeeded | It did what was asked |
| Rejected as invalid | What was sent was wrong: a missing field, an unknown code, a record that doesn't exist |
| Refused | Whoever sent it wasn't allowed to: a revoked key, a missing permission, an address outside the allowed list, or too many requests |
| Failed on our side | Something went wrong in Practor. Quote the request id if you contact us |

## Export the audit log

1. Filter the list to what you need.
2. Press **Export CSV**.

The file holds the events that match your filters, with times in UTC. If more than 10,000 match, the page says so above the list, and the file holds the newest 10,000. Narrow the dates to export the rest. Exporting is itself recorded in the audit log, as **Audit log exported**.

## Related

- [Connect your own software to Practor](/help/security-and-integrations/connect-your-own-software-to-practor)
- [Keep your account safe](/help/your-account/keep-your-account-safe)
