The [Permission history] tab opens for any organization admin. Exporting audit logs and access logs to a file, and forwarding events to a SIEM, are turned on by Tiro to match your organization’s contract, so the tab may stay locked when you open it. Contact your account manager or partners@theplato.io if you need them.
What gets recorded?
Audit events cover only the actions that need evidence of who did what, and when. These are the actions recorded today.
Each record holds the time it occurred (UTC), the action type, whether it succeeded, the acting user, the target organization, the role values before and after the change, and the IP address and browser information behind the request. Records of personal data handling, such as viewing and deleting notes, will join the same screen and SIEM feed once verification is complete.
Review permission history
The [Permission history] tab under the [Audit] menu shows role grants, changes, and revocations for organization members over a date range you pick.- Open your profile at the top left, then go to [Settings] → [Organization Settings] → [Organization].
- Open the [Audit] menu on the left and select the [Permission history] tab.
- Pick a date range to see the member, the roles before and after, who performed the change, and when. Use [Load more] below the list to keep loading.
Export audit logs to CSV
For longer periods, or when you need a file to keep, create and download a log file from the [Audit logs] tab. Files aren’t ready instantly; they’re prepared in the background after you request one.1
Pick a period and action types
Choose a start and end date under [Select a date range], and narrow the results with the [Action type] filter if you need only certain actions. One file can cover up to 365 days. The most recent 15 minutes are excluded automatically because those records are still settling.
2
Give a download reason
Press [Create log file] and choose a [Download reason]. Pick one of Customer request, Incident investigation, Legal audit, Internal operations, or Periodic review, or select Other and write 10 to 200 characters of detail. The reason is stored with the audit record.
3
Download once it's ready
When the status in the request history below turns Ready, press [Download] to get the CSV file. The request history also shows when it was requested, the period, who requested it, the status, the record count, and the expiry time.
Export access logs
The [Access logs] tab covers the requests organization members send to Tiro servers. Each record holds the request time, the user, the source IP, browser information, the request path, and the response code. Access logs run at a far higher volume than audit logs, so they’re enabled separately based on your organization’s contract. Exporting works the same way as audit logs. Pick a period, request the file with [Create log file], and download it once it’s ready. Access logs have no action type filter, so you specify only the period.Stream events to your SIEM
If your company runs a SIEM such as Splunk, Microsoft Sentinel, or Elastic, you can receive your organization’s audit events there in near real time. Tiro delivers each event over HTTPS to an endpoint your company designates.What gets sent, and how
- Scope: Only audit events from data your organization owns. Events from other organizations are never mixed in.
- Events: The action types in the “What gets recorded?” table above are the default. Organizations with access logs enabled also receive access log query and export events. New event types are never sent automatically beyond the scope you agreed on.
- Format: A JSON body sent as an HTTPS POST. GZIP compression is available on request.
- Authentication: A header scheme your company designates, such as a Splunk HEC token or an Authorization header. Token values are handed over through a separate channel, never written into a form or an email.
- Latency and retries: Events usually arrive within a few minutes. Failed deliveries retry automatically for up to 2 hours, and for longer outages we agree on a manual reprocessing procedure with you.
Request an integration
1
Submit the request form
Fill in the SIEM integration request form with your contact, SIEM product, receiving endpoint, the data you want, and your target schedule. Don’t write secret values such as tokens into the form.
2
Confirm the scope and authentication
Your Tiro contact replies confirming the event scope, the authentication header, firewall allowlists, and the expected delivery volume and cost.
3
Verify a test event
Before delivery is switched on, we send one test event while the integration is still inactive. Together we check the action type, organization ID, and receive time of the event that landed in your SIEM.
4
Turn it on
Once your side confirms receipt, delivery is switched on. After go-live we keep watching the failure rate and latency, and if anything looks wrong we turn delivery off immediately and rotate the token.
SIEM delivery is the real-time path, while the CSV export on the audit log screen reads the retained originals. Both paths handle the same events but run independently, so you can always export from the screen again even when SIEM delivery has a problem.
Frequently asked questions
How long can I download a log file I created?
Each row in the request history shows its own expiry time. Past that time the status turns Expired and the file can’t be downloaded again. Create it again with the same conditions; a single request can cover up to 365 days. How long the original audit events are retained is set by your organization’s contract. Tell your account manager if you have a retention period you’re required to meet.Can I see who opened a note?
Note view and delete events are being recorded, but they’ll be added to the per-organization screen and the SIEM feed once verification is complete. Let your account manager know if you need them by a certain date.Can regular members see audit logs?
No. The [Organization] screen itself opens only for organization Admin users. Workspace admins and regular members don’t see the menu at all.Related pages: Organization Security · Enterprise plan · Workspace roles