Overview
The Activity Log shows organization-wide user activity rolled up by session rather than by individual event. Where the Audit Log lists every technical event, the Activity Log answers a simpler question: who was active, when, and for how long?
This is one of three related surfaces. See the Audit & Activity Logging Overview for how it relates to the asset-level Audit tab and the Application Audit Log.
Navigating there
From the left-hand navigation:Activity panel
The panel header shows the total number of recorded sessions, e.g.Activity (384).
Table columns
The table includes additional columns beyond what’s visible above the fold — scroll right within the panel to see the full set.
How sessions and audit events connect
Each Activity row is a summary of one session; the Audit Count column tells you how many individual events (API calls, AI actions, job triggers) occurred during that session. To see the underlying events, cross-reference the session’s time window against the Audit tab, filtered by user and date range.Common use cases
- Session review — see how long a user was active, and whether a session is still open
- Anomaly detection — spot unusually long sessions or an unexpected spike in audit count for a single session
- Access investigation — combine with the Application Audit Log to reconstruct exactly what a user did during a specific session
Filters
Currently, the Activity panel supports the ALL filter, alongside the standard sort, search, and export controls in the top-right of the panel.How this differs from the other two surfaces
Related pages
Logging Overview
See how this fits with the other two logging surfaces
Audit Log
Drill into the individual events that make up a session
Asset Audit
See a curated, business-readable audit trail for a single asset