Configuring Your Account
Understand Billing
Publishing
Analytics & Reporting
Engagement
AI and Automation
Social Listening
Sprout Integrations
Tagging
Customer Care
Salesforce Service Cloud
Instagram
Facebook
X
Tiktok
Threads
WhatsApp
LinkedIn
YouTube
Pinterest
Bluesky

What's included in audit trail logs?

Table of Contents

Sprout’s audit trail logs record actions users take across your account. The table below lists each event and a brief description of what it means. Some events depend on your plan or on specific features being enabled, so your exported logs may not include every event listed here.

Sprout Social Audit Events

Event Description
USER_LOGGED_IN A user signed in to Sprout (by password or SSO) on the web or mobile app. Records sign-ins only, not ongoing activity or session length.
USER_LOGGED_OUT A user signed out of Sprout on the web app (mobile sign-outs are not captured).
USER_LOGIN_FAILED A user failed to sign in, by SSO or username and password.
USER_PASSWORD_SET A user set their password for the first time.
USER_PASSWORD_UPDATED A user changed their password.
USER_UPDATED_EMAIL A user changed their account email in Personal Settings.
USER_INITIATED_EMAIL_VERIFICATION A user started email verification for their account.
USER_VERIFIED_EMAIL A user completed email verification.
USER_ENABLED_TWO_STEP A user enabled two-step verification on their account from the Security page.
USER_REQUIRED_TWO_STEP An Admin or Owner required two-step verification for the account from the Security page.
USER_CONFIGURED_TWO_STEP A user set up two-step verification after it was required.
USER_UPDATED_BACKUP_CODES_TWO_STEP A user regenerated their two-step backup codes.
EMAIL_TWO_STEP_GENERATED A two-step verification code was sent by email.
EMAIL_TWO_STEP_VERIFY_VALID A user entered a valid email two-step code.
EMAIL_TWO_STEP_VERIFY_INVALID A user entered an invalid email two-step code.
USER_INVITED An Admin invited additional users.
USER_DELETED An Admin deleted a user.
USER_RESENT_INVITE An Admin clicked Resend on a pending user's invite under Team Members.
USER_REVOKED_INVITE An Admin clicked Revoke on a pending user's invite under Team Members.
USER_SEATS_ADDED Seats were added to the account.
USER_SEATS_DELETED Seats were removed from the account.
USER_WELCOME_FORM_COMPLETED A new user completed the welcome form.
USER_UPDATED A user's details were updated.
USER_CREATE_FAILED A user could not be created.
USER_DELETE_FAILED A user could not be deleted.
USER_UPDATE_FAILED A user could not be updated.
USER_UPDATED_BUSINESS_NAME A user changed the business name in Account Settings.
USER_UPDATED_CROSS_GROUP_ASSIGNMENTS A user changed the Cross-Group Task Assignments setting.
USER_UPDATED_FB_PAGE_NAME_DISPLAY_SETTING A user changed the Facebook Page Name Display setting.
USER_UPDATED_OPENAI_INTEGRATION A user changed the AI integration setting.
USER_STATUS_CHANGED A user's availability in Sprout changed (Available or Unavailable), set manually from the user menu, by the system, or automatically after a period of inactivity.
USER_TEAM_CREATED A user team was created.
USER_TEAM_DELETED A user team was deleted.
USER_TEAM_MEMBERS_UPDATED A user team's members changed.
USER_TEAM_METADATA_UPDATED A user team's name or details changed.
ROLE_CREATED An Admin created a role.
ROLE_UPDATED An Admin updated a role's permissions.
ROLE_DELETED An Admin deleted a role.
ROLE_ASSIGNED An Admin assigned a role to a user.
ROLE_UNASSIGNED An Admin removed a role from a user.
ROLE_ASSIGNMENT_FAILED A role could not be assigned to a user.
ROLE_UNASSIGNMENT_FAILED A role could not be removed from a user.
USER_PERMISSIONS_UPDATED An Admin updated a user's Company or Feature permissions.
PROFILE_PERMISSIONS_UPDATED An Admin updated a user's profile permissions.
PROFILE_PERMISSIONS_CREATED An Admin set profile permissions for a user.
PROFILE_PERMISSION_SET_CREATED An Admin created a profile permission set.
PROFILE_PERMISSION_SET_UPDATED An Admin updated a profile permission set.
PROFILE_PERMISSION_SET_DELETED An Admin deleted a profile permission set.
PROFILE_PERMISSION_SET_ASSIGNED An Admin assigned a profile permission set to a user.
PROFILE_PERMISSION_SET_UNASSIGNED An Admin removed a profile permission set from a user.
PROFILE_PERMISSION_SET_ASSIGNMENT_FAILED A profile permission set could not be assigned.
GROUP_CREATED An Admin created a group.
GROUP_DELETED An Admin deleted a group.
USER_ADDED_TO_GROUP An Admin added a user to a group.
USER_REMOVED_FROM_GROUP An Admin removed a user from a group.
PROFILE_CONNECTED An Admin connected a new social profile using the Connect a Profile option.
PROFILE_REAUTHED An Admin reauthorized a profile that had expired.
PROFILE_DELETED An Admin deleted a social profile.
PROFILE_ADDED_TO_GROUP An Admin added a connected profile to a group.
SSO_ENABLED An Admin with Manage SSO uploaded an SSO XML file and enabled SSO under Single Sign On settings.
SSO_EDITED_SAML_SETTINGS An Admin with Manage SSO edited SAML settings under Single Sign On > Edit SAML.
SSO_ENABLED_PASSWORD An Admin with Manage SSO enabled Sprout-managed passwords under Single Sign On.
SSO_DISABLED_PASSWORD An Admin with Manage SSO disabled Sprout-managed passwords under Single Sign On.
JIT_USER_CREATED A new user was created via SSO Just-in-Time (JIT) provisioning.
JIT_ENABLED An SSO Admin enabled JIT provisioning.
JIT_DISABLED An SSO Admin disabled JIT provisioning.
SCIM_CONFIG_CREATED An Admin set up SCIM user provisioning.
SCIM_CONFIG_UPDATED An Admin changed the SCIM provisioning mode (Disabled, Test, or Live).
SCIM_CONFIG_DELETED An Admin removed the SCIM configuration.
OAUTH_CLIENT_CREATED A user created an API client.
OAUTH_CLIENT_UPDATED A user updated an API client.
OAUTH_CLIENT_DELETED A user deleted an API client.
OAUTH_CLIENT_SECRET_REGENERATED A user regenerated an API client secret.
OAUTH_TOKENS_ISSUED API access tokens were issued to a client.
PUB_PUBLISHED_POST A user published a post to a social profile.
DELETED_PUBLISHED_POST A user deleted a published post.
PUB_APPROVED_POST A user approved a post in Needs Approval.
PUB_EDITED_POST A user edited a pending or scheduled post via the pencil icon.
PUB_CREATED_POST A user created a pending post (draft, scheduled, queued, or needs approval).
PUB_DELETED_PENDING_POST A user deleted a pending post (scheduled, queued, needs approval, or draft).
PUB_ENABLED_QUEUE A user with the Manage Sprout Queue permission re-enabled the Sprout Queue (Settings > Publishing > Sprout Queue).
PUB_DISABLED_QUEUE A user with the Manage Sprout Queue permission disabled the Sprout Queue (Settings > Publishing > Sprout Queue).
PUB_BULK_IMPORT A user imported messages via Bulk Post CSV.
PUB_GLOBAL_PAUSED An Admin paused publishing across the account (Stop posts).
PUB_GLOBAL_RESUMED An Admin resumed publishing across the account (Resume posts).
AUTOMATED_RULE_CREATED A user created an automation rule.
AUTOMATED_RULE_UPDATED A user updated an automation rule.
AUTOMATED_RULE_DELETED A user deleted an automation rule.
AUTOMATION_PIPELINE_CREATED A user created an automation pipeline.
AUTOMATION_PIPELINE_UPDATED A user updated an automation pipeline.
AUTOMATION_PIPELINE_DELETED A user deleted an automation pipeline.
TAG_DELETED A user deleted a tag.
TAG_COLLECTION_DELETED A user deleted a tag collection.
CASE_UPDATED A user updated a Case (status, assignee, priority, type, or tags).
CASE_DELETED A user deleted a Case.
COMMENT_ADDED A user added an internal comment to a Case.
COMMENT_EDITED A user edited an internal comment on a Case.
COMMENT_DELETED A user deleted an internal comment from a Case.
CASE_QUEUE_CREATED A user created a case queue.
CASE_QUEUE_UPDATED A user updated a case queue.
CASE_QUEUE_DELETED A user deleted a case queue.
INBOX_BULK_ACTION_SELECTED_ALL A user started a bulk action on all selected inbox items.
INBOX_BULK_ACTION_SELECTED_ALL_COMPLETE A bulk inbox action completed.
INBOX_BULK_ACTION_SELECTED_ALL_FAILED A bulk inbox action failed.
INBOX_BULK_ACTION_SELECTED_ALL_PARTIALLY_FAILED A bulk inbox action partially failed.
MACRO_CREATED An Admin created a macro in Settings.
MACRO_UPDATED An Admin updated a macro in Settings.
MACRO_DELETED An Admin deleted a macro in Settings.
PROFILE_LIST_CREATED A user created a profile list.
PROFILE_LIST_UPDATED A user updated a profile list.
PROFILE_LIST_DELETED A user deleted a profile list.
PROFILE_LIST_MEMBER_ADDED A user added a social profile to a profile list.
PROFILE_LIST_MEMBER_REMOVED A user removed a social profile from a profile list.
EXPORTED_AUDIT_LOGS A user with Manage Permissions exported audit logs from the Groups & Social Profiles or Roles & Team Members page.
EXPORTED_USER_PERMISSIONS A user exported user permissions from the Groups & Social Profiles or Roles & Team Members page.
CUSTOM_METRICS_CREATED A user with Custom Metric edit permissions created a Custom Metric for the Group or Customer.
CUSTOM_METRICS_UPDATED A user with Custom Metric edit permissions edited a Custom Metric for the Group or Customer.
CUSTOM_METRICS_DELETED A user with Custom Metric edit permissions deleted a Custom Metric for the Group or Customer.
REPORT_CREATED A user created a report (private or shared).
REPORT_DELETED A user deleted a report.
REPORT_PUBLICIZED A user changed a report from private to shared.
REPORT_PRIVATIZED A user changed a report from shared to private.

Guardian Audit Events

The following events are part of Guardian by Sprout Social, a paid add-on. They appear in your audit trail only if your account has the Guardian add-on.

Event Description
KEYWORD_LIST_SETTINGS_CREATED A user created a blocked-words list.
KEYWORD_LIST_SETTINGS_UPDATED A user updated a blocked-words list (added or removed a word or phrase).
KEYWORD_LIST_SETTINGS_DELETED A user deleted a blocked-words list.
KEYWORD_LIST_SETTINGS_ENABLED A user turned on a blocked-words list.
KEYWORD_LIST_SETTINGS_DISABLED A user turned off a blocked-words list.
CONTENT_VALIDATION_BLOCKED A user's content was blocked for matching a blocked-words list.
EMPLOYEE_ADVOCACY_CONTENT_VALIDATION_BLOCKED An Employee Advocacy user's content was blocked for matching a blocked-words list.
DATA_MASKING_SETTINGS_UPDATED A user changed data-masking settings (a PII type such as email or phone number was enabled/disabled, or a custom data type was added, edited, or removed).
UNMASK_SENSITIVE_DATA A user with Unmask Message permissions unmasked sensitive data in a message.
SECURE_FORM_CREATED An Admin created a secure form in Settings.
SECURE_FORM_UPDATED An Admin updated a secure form in Settings.
SECURE_FORM_DELETED An Admin deleted a secure form in Settings.
SECURE_FORM_ENABLED An Admin enabled a secure form in Settings.
SECURE_FORM_DISABLED An Admin disabled a secure form in Settings.
SECURE_FORM_INSTANCE_SHARED A user sent a secure form to an end user.
SECURE_FORM_INSTANCE_REVEALED A user revealed data submitted in a secure form.
SECURE_FORM_INSTANCE_EXPIRED A shared secure form expired.

Additional information

You may also see post-specific terms that help you track the history of a post:

  • Pending post ID — the ID of a post not yet published to a social network (for example, a scheduled, queued, or draft post).
  • Post ID — the ID of a post that was published to a network.

For IT-admin needs, the export also includes these columns describing the user who generated each event:

  • IP Address — the IP address of the user.
  • Client Type — the user’s client information (browser, device, version).
  • City — the user’s city.
  • Region — the user’s region.
  • Country — the user’s country.
  • Continent — the user’s continent.

Was this article helpful?

0 out of 0 found this helpful

Table of Contents