Skip to main content

Audit Logs

The Audit Logs provide an overview of security-related events within Cryptomator Hub. These logs allow administrators to track important account and vault-related actions.

note

Audit Logs are not available with a Community License.

Viewing the Audit Log

The logs are displayed in a structured table containing the following columns:

  • Timestamp – The exact time of the event.
  • Event – The type of event that occurred.
  • Details – Additional information about the event.

Audit Logs Table View

Filtering Audit Logs

To refine the displayed logs, a filtering function is available:

Audit Log Filtering Options

  • Date Range Filter: Allows filtering logs between two specific dates.
  • Event Type Filter: A multi-select dropdown enables filtering by event type.

Audit Log Filtering Options

Event Types

The following events are logged:

Device

  • Register Device - A user registered a new device. This can be, e.g., a Cryptomator app (desktop/mobile) to unlock a vault or a web browser to access Cryptomator Hub.
  • Remove Device – A user removed a device.

Web of Trust

Vault

  • Add Vault Member – A vault owner added a member to a vault. This only adds the member but does not derive the vault key for the new member.
  • Create Vault – A user created a vault.
  • Grant Vault Access – A user derived the vault key for the new member.
  • Retrieve Vault Key – A user retrieved a vault key. This happens when a user unlocks a vault but also, e.g., when an owner manages the vault. The IP address and device information are optional for legacy reasons.
  • Remove Vault Member – A vault owner removed a member from a vault.
  • Update Vault Member – A vault owner changed a member's role (owner or user).
  • Update Vault – A vault owner updated the vault metadata. This includes the vault name or description.

Account

Emergency Access (Enterprise Only)

  • Emergency Access Setup – A vault owner set up or updated the Emergency Access configuration for a vault (e.g. by assigning council members in Vault Details).
  • Emergency Access Settings Updated – An admin changed the global Emergency Access settings.
  • Emergency Access Recovery Started – A council member started an Emergency Access recovery process.
  • Emergency Access Recovery Approved – A council member approved a running recovery process.
  • Emergency Access Recovery Completed – A council member completed a recovery process.
  • Emergency Access Recovery Aborted – A council member aborted a running recovery process.
note

When a council member starts a recovery process, both Emergency Access Recovery Started and Emergency Access Recovery Approved are logged.

Legacy

  • Claim Vault Ownership – A user claimed vault ownership. This event is logged when a vault created with hub pre 1.3.0 is claimed by the vault creator using the Vault Admin Password.