Who deleted those contacts? Audit logs and team roles
If a batch of contacts vanished last Tuesday, you should be able to say who removed them, when, and from which IP address. That takes two things: an audit log that records consequential actions in a way that shows if someone tampers with it, and roles that give each person only the access they need. In Email Digit, Owners and Admins can read that log, and five roles are enforced on the server.
What an audit log is for
An audit log is not an activity feed. Its job is to answer a question after something has gone wrong, or when someone asks you to prove what happened. A useful one records, for every consequential action:
- Who did it: a named person, not “an admin”.
- What they did, and to what.
- When, to the second.
- From where: the IP address and the browser or client.
It also has to be trustworthy. A log anyone can quietly edit proves nothing, because the person you would want to find is the one with a reason to edit it. And it has to be readable by the right people without being readable by everyone, since it records who works in your account and where they sign in from.
What Email Digit records
Owners and Admins can open the workspace audit log. Each entry carries the person, the action, what it was done to, the details, the IP address, the browser and the time. Actions that change who you can email, or what leaves your account, are among those recorded:
- consent changes on a contact;
- deleting contacts;
- imports;
- sunset actions, such as suppressing silent contacts for marketing;
- changes to your do-not-send list;
- creating and revoking API keys.
Tamper-evident, not tamper-proof
These two words get used interchangeably and mean different things:
| Term | Promise |
|---|---|
| Tamper-proof | Nobody can change an entry |
| Tamper-evident | If an entry is changed or removed, that can be detected |
Email Digit’s log is tamper-evident. If an entry is edited or deleted, the change can be detected. It is not tamper-proof: the application can still change a row, and the change shows. We would rather say that than claim a guarantee the system does not give.
Our own staff leave a trail too
Support sometimes needs to look at a workspace’s data to answer a question. When someone at Email Digit opens the read-only support view of your workspace’s data, the visit is written to your own audit log, where your Owners and Admins can see it. A full export or erasure of a workspace by our staff is audited as well. Support access to your data is never silent.
Five roles, enforced on the server
The log tells you what happened. Roles decide what could happen in the first place. Each role includes everything the one above it in this table can do:
| Role | Adds the ability to |
|---|---|
| Viewer | Read the workspace (everything except the audit log), and change nothing |
| Sender | Send campaigns and run automations, and handle replies in the inbox |
| Editor | Change content: campaigns, contacts, automations, emails and brand |
| Admin | Manage sending domains, API keys, webhooks, connected mailboxes and the do-not-send list |
| Owner | Delete the workspace or change its owner |
“Enforced on the server” matters. A permission that is only a hidden button can be bypassed by anyone who calls the API directly. In Email Digit the server checks the role on every request, and a refused action comes back with a message naming the role it needs.
Putting it together
- Give people the smallest role that fits. A colleague who reads reports is a Viewer. Someone who answers replies is a Sender. Only the people who manage your domains and keys need Admin.
- Keep Owners few. Owner is the one role that can delete the workspace.
- Check the log after anything surprising, such as a drop in contacts or a key you do not recognise.
- Turn on two-factor sign-in. It is optional, not enforced, and the log is only as meaningful as the accounts behind it.
A worked example. Your contact count dropped by a few hundred overnight. An Admin opens the audit log and looks for delete actions: one entry, from a teammate, at 18:42, from an IP address your office uses, removing a selection of contacts. The details show how many. Now the conversation is about whether the delete was intended, not about whether it happened, and the answer took a minute rather than an afternoon of guessing. If the log showed an IP address nobody recognises, that would be a different conversation, starting with the account’s password and two-factor settings.
The edges worth knowing:
- The audit log is visible to Owners and Admins only.
- The Lite plan includes one seat, so roles start to matter from the next plan up.
- Tamper-evident means detection, not prevention.
Sunset actions are covered in more detail in the sunset list guide.