What's included in audit trail logs?
Table of Contents
Sprout’s audit trail logs record actions users take across your account. The table below lists each event and a brief description of what it means. Some events depend on your plan or on specific features being enabled, so your exported logs may not include every event listed here.
Sprout Social Audit Events
| Event | Description |
|---|---|
| USER_LOGGED_IN | A user signed in to Sprout (by password or SSO) on the web or mobile app. Records sign-ins only, not ongoing activity or session length. |
| USER_LOGGED_OUT | A user signed out of Sprout on the web app (mobile sign-outs are not captured). |
| USER_LOGIN_FAILED | A user failed to sign in, by SSO or username and password. |
| USER_PASSWORD_SET | A user set their password for the first time. |
| USER_PASSWORD_UPDATED | A user changed their password. |
| USER_UPDATED_EMAIL | A user changed their account email in Personal Settings. |
| USER_INITIATED_EMAIL_VERIFICATION | A user started email verification for their account. |
| USER_VERIFIED_EMAIL | A user completed email verification. |
| USER_ENABLED_TWO_STEP | A user enabled two-step verification on their account from the Security page. |
| USER_REQUIRED_TWO_STEP | An Admin or Owner required two-step verification for the account from the Security page. |
| USER_CONFIGURED_TWO_STEP | A user set up two-step verification after it was required. |
| USER_UPDATED_BACKUP_CODES_TWO_STEP | A user regenerated their two-step backup codes. |
| EMAIL_TWO_STEP_GENERATED | A two-step verification code was sent by email. |
| EMAIL_TWO_STEP_VERIFY_VALID | A user entered a valid email two-step code. |
| EMAIL_TWO_STEP_VERIFY_INVALID | A user entered an invalid email two-step code. |
| USER_INVITED | An Admin invited additional users. |
| USER_DELETED | An Admin deleted a user. |
| USER_RESENT_INVITE | An Admin clicked Resend on a pending user's invite under Team Members. |
| USER_REVOKED_INVITE | An Admin clicked Revoke on a pending user's invite under Team Members. |
| USER_SEATS_ADDED | Seats were added to the account. |
| USER_SEATS_DELETED | Seats were removed from the account. |
| USER_WELCOME_FORM_COMPLETED | A new user completed the welcome form. |
| USER_UPDATED | A user's details were updated. |
| USER_CREATE_FAILED | A user could not be created. |
| USER_DELETE_FAILED | A user could not be deleted. |
| USER_UPDATE_FAILED | A user could not be updated. |
| USER_UPDATED_BUSINESS_NAME | A user changed the business name in Account Settings. |
| USER_UPDATED_CROSS_GROUP_ASSIGNMENTS | A user changed the Cross-Group Task Assignments setting. |
| USER_UPDATED_FB_PAGE_NAME_DISPLAY_SETTING | A user changed the Facebook Page Name Display setting. |
| USER_UPDATED_OPENAI_INTEGRATION | A user changed the AI integration setting. |
| USER_STATUS_CHANGED | A user's availability in Sprout changed (Available or Unavailable), set manually from the user menu, by the system, or automatically after a period of inactivity. |
| USER_TEAM_CREATED | A user team was created. |
| USER_TEAM_DELETED | A user team was deleted. |
| USER_TEAM_MEMBERS_UPDATED | A user team's members changed. |
| USER_TEAM_METADATA_UPDATED | A user team's name or details changed. |
| ROLE_CREATED | An Admin created a role. |
| ROLE_UPDATED | An Admin updated a role's permissions. |
| ROLE_DELETED | An Admin deleted a role. |
| ROLE_ASSIGNED | An Admin assigned a role to a user. |
| ROLE_UNASSIGNED | An Admin removed a role from a user. |
| ROLE_ASSIGNMENT_FAILED | A role could not be assigned to a user. |
| ROLE_UNASSIGNMENT_FAILED | A role could not be removed from a user. |
| USER_PERMISSIONS_UPDATED | An Admin updated a user's Company or Feature permissions. |
| PROFILE_PERMISSIONS_UPDATED | An Admin updated a user's profile permissions. |
| PROFILE_PERMISSIONS_CREATED | An Admin set profile permissions for a user. |
| PROFILE_PERMISSION_SET_CREATED | An Admin created a profile permission set. |
| PROFILE_PERMISSION_SET_UPDATED | An Admin updated a profile permission set. |
| PROFILE_PERMISSION_SET_DELETED | An Admin deleted a profile permission set. |
| PROFILE_PERMISSION_SET_ASSIGNED | An Admin assigned a profile permission set to a user. |
| PROFILE_PERMISSION_SET_UNASSIGNED | An Admin removed a profile permission set from a user. |
| PROFILE_PERMISSION_SET_ASSIGNMENT_FAILED | A profile permission set could not be assigned. |
| GROUP_CREATED | An Admin created a group. |
| GROUP_DELETED | An Admin deleted a group. |
| USER_ADDED_TO_GROUP | An Admin added a user to a group. |
| USER_REMOVED_FROM_GROUP | An Admin removed a user from a group. |
| PROFILE_CONNECTED | An Admin connected a new social profile using the Connect a Profile option. |
| PROFILE_REAUTHED | An Admin reauthorized a profile that had expired. |
| PROFILE_DELETED | An Admin deleted a social profile. |
| PROFILE_ADDED_TO_GROUP | An Admin added a connected profile to a group. |
| SSO_ENABLED | An Admin with Manage SSO uploaded an SSO XML file and enabled SSO under Single Sign On settings. |
| SSO_EDITED_SAML_SETTINGS | An Admin with Manage SSO edited SAML settings under Single Sign On > Edit SAML. |
| SSO_ENABLED_PASSWORD | An Admin with Manage SSO enabled Sprout-managed passwords under Single Sign On. |
| SSO_DISABLED_PASSWORD | An Admin with Manage SSO disabled Sprout-managed passwords under Single Sign On. |
| JIT_USER_CREATED | A new user was created via SSO Just-in-Time (JIT) provisioning. |
| JIT_ENABLED | An SSO Admin enabled JIT provisioning. |
| JIT_DISABLED | An SSO Admin disabled JIT provisioning. |
| SCIM_CONFIG_CREATED | An Admin set up SCIM user provisioning. |
| SCIM_CONFIG_UPDATED | An Admin changed the SCIM provisioning mode (Disabled, Test, or Live). |
| SCIM_CONFIG_DELETED | An Admin removed the SCIM configuration. |
| OAUTH_CLIENT_CREATED | A user created an API client. |
| OAUTH_CLIENT_UPDATED | A user updated an API client. |
| OAUTH_CLIENT_DELETED | A user deleted an API client. |
| OAUTH_CLIENT_SECRET_REGENERATED | A user regenerated an API client secret. |
| OAUTH_TOKENS_ISSUED | API access tokens were issued to a client. |
| PUB_PUBLISHED_POST | A user published a post to a social profile. |
| DELETED_PUBLISHED_POST | A user deleted a published post. |
| PUB_APPROVED_POST | A user approved a post in Needs Approval. |
| PUB_EDITED_POST | A user edited a pending or scheduled post via the pencil icon. |
| PUB_CREATED_POST | A user created a pending post (draft, scheduled, queued, or needs approval). |
| PUB_DELETED_PENDING_POST | A user deleted a pending post (scheduled, queued, needs approval, or draft). |
| PUB_ENABLED_QUEUE | A user with the Manage Sprout Queue permission re-enabled the Sprout Queue (Settings > Publishing > Sprout Queue). |
| PUB_DISABLED_QUEUE | A user with the Manage Sprout Queue permission disabled the Sprout Queue (Settings > Publishing > Sprout Queue). |
| PUB_BULK_IMPORT | A user imported messages via Bulk Post CSV. |
| PUB_GLOBAL_PAUSED | An Admin paused publishing across the account (Stop posts). |
| PUB_GLOBAL_RESUMED | An Admin resumed publishing across the account (Resume posts). |
| AUTOMATED_RULE_CREATED | A user created an automation rule. |
| AUTOMATED_RULE_UPDATED | A user updated an automation rule. |
| AUTOMATED_RULE_DELETED | A user deleted an automation rule. |
| AUTOMATION_PIPELINE_CREATED | A user created an automation pipeline. |
| AUTOMATION_PIPELINE_UPDATED | A user updated an automation pipeline. |
| AUTOMATION_PIPELINE_DELETED | A user deleted an automation pipeline. |
| TAG_DELETED | A user deleted a tag. |
| TAG_COLLECTION_DELETED | A user deleted a tag collection. |
| CASE_UPDATED | A user updated a Case (status, assignee, priority, type, or tags). |
| CASE_DELETED | A user deleted a Case. |
| COMMENT_ADDED | A user added an internal comment to a Case. |
| COMMENT_EDITED | A user edited an internal comment on a Case. |
| COMMENT_DELETED | A user deleted an internal comment from a Case. |
| CASE_QUEUE_CREATED | A user created a case queue. |
| CASE_QUEUE_UPDATED | A user updated a case queue. |
| CASE_QUEUE_DELETED | A user deleted a case queue. |
| INBOX_BULK_ACTION_SELECTED_ALL | A user started a bulk action on all selected inbox items. |
| INBOX_BULK_ACTION_SELECTED_ALL_COMPLETE | A bulk inbox action completed. |
| INBOX_BULK_ACTION_SELECTED_ALL_FAILED | A bulk inbox action failed. |
| INBOX_BULK_ACTION_SELECTED_ALL_PARTIALLY_FAILED | A bulk inbox action partially failed. |
| MACRO_CREATED | An Admin created a macro in Settings. |
| MACRO_UPDATED | An Admin updated a macro in Settings. |
| MACRO_DELETED | An Admin deleted a macro in Settings. |
| PROFILE_LIST_CREATED | A user created a profile list. |
| PROFILE_LIST_UPDATED | A user updated a profile list. |
| PROFILE_LIST_DELETED | A user deleted a profile list. |
| PROFILE_LIST_MEMBER_ADDED | A user added a social profile to a profile list. |
| PROFILE_LIST_MEMBER_REMOVED | A user removed a social profile from a profile list. |
| EXPORTED_AUDIT_LOGS | A user with Manage Permissions exported audit logs from the Groups & Social Profiles or Roles & Team Members page. |
| EXPORTED_USER_PERMISSIONS | A user exported user permissions from the Groups & Social Profiles or Roles & Team Members page. |
| CUSTOM_METRICS_CREATED | A user with Custom Metric edit permissions created a Custom Metric for the Group or Customer. |
| CUSTOM_METRICS_UPDATED | A user with Custom Metric edit permissions edited a Custom Metric for the Group or Customer. |
| CUSTOM_METRICS_DELETED | A user with Custom Metric edit permissions deleted a Custom Metric for the Group or Customer. |
| REPORT_CREATED | A user created a report (private or shared). |
| REPORT_DELETED | A user deleted a report. |
| REPORT_PUBLICIZED | A user changed a report from private to shared. |
| REPORT_PRIVATIZED | A user changed a report from shared to private. |
Guardian Audit Events
The following events are part of Guardian by Sprout Social, a paid add-on. They appear in your audit trail only if your account has the Guardian add-on.
| Event | Description |
|---|---|
| KEYWORD_LIST_SETTINGS_CREATED | A user created a blocked-words list. |
| KEYWORD_LIST_SETTINGS_UPDATED | A user updated a blocked-words list (added or removed a word or phrase). |
| KEYWORD_LIST_SETTINGS_DELETED | A user deleted a blocked-words list. |
| KEYWORD_LIST_SETTINGS_ENABLED | A user turned on a blocked-words list. |
| KEYWORD_LIST_SETTINGS_DISABLED | A user turned off a blocked-words list. |
| CONTENT_VALIDATION_BLOCKED | A user's content was blocked for matching a blocked-words list. |
| EMPLOYEE_ADVOCACY_CONTENT_VALIDATION_BLOCKED | An Employee Advocacy user's content was blocked for matching a blocked-words list. |
| DATA_MASKING_SETTINGS_UPDATED | A user changed data-masking settings (a PII type such as email or phone number was enabled/disabled, or a custom data type was added, edited, or removed). |
| UNMASK_SENSITIVE_DATA | A user with Unmask Message permissions unmasked sensitive data in a message. |
| SECURE_FORM_CREATED | An Admin created a secure form in Settings. |
| SECURE_FORM_UPDATED | An Admin updated a secure form in Settings. |
| SECURE_FORM_DELETED | An Admin deleted a secure form in Settings. |
| SECURE_FORM_ENABLED | An Admin enabled a secure form in Settings. |
| SECURE_FORM_DISABLED | An Admin disabled a secure form in Settings. |
| SECURE_FORM_INSTANCE_SHARED | A user sent a secure form to an end user. |
| SECURE_FORM_INSTANCE_REVEALED | A user revealed data submitted in a secure form. |
| SECURE_FORM_INSTANCE_EXPIRED | A shared secure form expired. |
Additional information
You may also see post-specific terms that help you track the history of a post:
- Pending post ID — the ID of a post not yet published to a social network (for example, a scheduled, queued, or draft post).
- Post ID — the ID of a post that was published to a network.
For IT-admin needs, the export also includes these columns describing the user who generated each event:
- IP Address — the IP address of the user.
- Client Type — the user’s client information (browser, device, version).
- City — the user’s city.
- Region — the user’s region.
- Country — the user’s country.
- Continent — the user’s continent.
Was this article helpful?