Skip to main content
Available to the Admin role in Enterprise organizations only. Tiro records the key administrative actions taken in your organization as audit events. An organization admin reviews these records and exports them to a CSV file from the [Audit] menu on the [Organization] screen. If your company runs a SIEM, you can receive the same events there in near real time.
The [Permission history] tab opens for any organization admin. Exporting audit logs and access logs to a file, and forwarding events to a SIEM, are turned on by Tiro to match your organization’s contract, so the tab may stay locked when you open it. Contact your account manager or partners@theplato.io if you need them.

What gets recorded?

Audit events cover only the actions that need evidence of who did what, and when. These are the actions recorded today. Each record holds the time it occurred (UTC), the action type, whether it succeeded, the acting user, the target organization, the role values before and after the change, and the IP address and browser information behind the request. Records of personal data handling, such as viewing and deleting notes, will join the same screen and SIEM feed once verification is complete.
Viewing or exporting audit logs is itself recorded as an audit event, so you can see who took the logs as well.

Review permission history

The [Permission history] tab under the [Audit] menu shows role grants, changes, and revocations for organization members over a date range you pick.
  1. Open your profile at the top left, then go to [Settings][Organization Settings][Organization].
  2. Open the [Audit] menu on the left and select the [Permission history] tab.
  3. Pick a date range to see the member, the roles before and after, who performed the change, and when. Use [Load more] below the list to keep loading.
Records for members who have left show Deleted user in place of a name.

Export audit logs to CSV

For longer periods, or when you need a file to keep, create and download a log file from the [Audit logs] tab. Files aren’t ready instantly; they’re prepared in the background after you request one.
1

Pick a period and action types

Choose a start and end date under [Select a date range], and narrow the results with the [Action type] filter if you need only certain actions. One file can cover up to 365 days. The most recent 15 minutes are excluded automatically because those records are still settling.
2

Give a download reason

Press [Create log file] and choose a [Download reason]. Pick one of Customer request, Incident investigation, Legal audit, Internal operations, or Periodic review, or select Other and write 10 to 200 characters of detail. The reason is stored with the audit record.
3

Download once it's ready

When the status in the request history below turns Ready, press [Download] to get the CSV file. The request history also shows when it was requested, the period, who requested it, the status, the record count, and the expiry time.
A log file moves through QueuedCreatingReady. Once a prepared file passes the expiry time shown, it turns Expired and can no longer be downloaded. Just create it again with the same conditions.
If the period you picked holds too many records, the request can end as Failed. Split the period and request it again. If it failed because the period reaches into long-term storage, ask your account manager to restore it.

Export access logs

The [Access logs] tab covers the requests organization members send to Tiro servers. Each record holds the request time, the user, the source IP, browser information, the request path, and the response code. Access logs run at a far higher volume than audit logs, so they’re enabled separately based on your organization’s contract. Exporting works the same way as audit logs. Pick a period, request the file with [Create log file], and download it once it’s ready. Access logs have no action type filter, so you specify only the period.

Stream events to your SIEM

If your company runs a SIEM such as Splunk, Microsoft Sentinel, or Elastic, you can receive your organization’s audit events there in near real time. Tiro delivers each event over HTTPS to an endpoint your company designates.

What gets sent, and how

  • Scope: Only audit events from data your organization owns. Events from other organizations are never mixed in.
  • Events: The action types in the “What gets recorded?” table above are the default. Organizations with access logs enabled also receive access log query and export events. New event types are never sent automatically beyond the scope you agreed on.
  • Format: A JSON body sent as an HTTPS POST. GZIP compression is available on request.
  • Authentication: A header scheme your company designates, such as a Splunk HEC token or an Authorization header. Token values are handed over through a separate channel, never written into a form or an email.
  • Latency and retries: Events usually arrive within a few minutes. Failed deliveries retry automatically for up to 2 hours, and for longer outages we agree on a manual reprocessing procedure with you.
A single event is made up of the following fields.

Request an integration

1

Submit the request form

Fill in the SIEM integration request form with your contact, SIEM product, receiving endpoint, the data you want, and your target schedule. Don’t write secret values such as tokens into the form.
2

Confirm the scope and authentication

Your Tiro contact replies confirming the event scope, the authentication header, firewall allowlists, and the expected delivery volume and cost.
3

Verify a test event

Before delivery is switched on, we send one test event while the integration is still inactive. Together we check the action type, organization ID, and receive time of the event that landed in your SIEM.
4

Turn it on

Once your side confirms receipt, delivery is switched on. After go-live we keep watching the failure rate and latency, and if anything looks wrong we turn delivery off immediately and rotate the token.
SIEM delivery is the real-time path, while the CSV export on the audit log screen reads the retained originals. Both paths handle the same events but run independently, so you can always export from the screen again even when SIEM delivery has a problem.

Frequently asked questions

How long can I download a log file I created?

Each row in the request history shows its own expiry time. Past that time the status turns Expired and the file can’t be downloaded again. Create it again with the same conditions; a single request can cover up to 365 days. How long the original audit events are retained is set by your organization’s contract. Tell your account manager if you have a retention period you’re required to meet.

Can I see who opened a note?

Note view and delete events are being recorded, but they’ll be added to the per-organization screen and the SIEM feed once verification is complete. Let your account manager know if you need them by a certain date.

Can regular members see audit logs?

No. The [Organization] screen itself opens only for organization Admin users. Workspace admins and regular members don’t see the menu at all.
Related pages: Organization Security · Enterprise plan · Workspace roles