Skip to main content

Overview

The Activity Log shows organization-wide user activity rolled up by session rather than by individual event. Where the Audit Log lists every technical event, the Activity Log answers a simpler question: who was active, when, and for how long?
Image
This is one of three related surfaces. See the Audit & Activity Logging Overview for how it relates to the asset-level Audit tab and the Application Audit Log.
From the left-hand navigation:
Activity sits next to Audit as a tab within the Log section of Command Center.

Activity panel

The panel header shows the total number of recorded sessions, e.g. Activity (384).

Table columns

The table includes additional columns beyond what’s visible above the fold — scroll right within the panel to see the full set.

How sessions and audit events connect

Each Activity row is a summary of one session; the Audit Count column tells you how many individual events (API calls, AI actions, job triggers) occurred during that session. To see the underlying events, cross-reference the session’s time window against the Audit tab, filtered by user and date range.

Common use cases

  • Session review — see how long a user was active, and whether a session is still open
  • Anomaly detection — spot unusually long sessions or an unexpected spike in audit count for a single session
  • Access investigation — combine with the Application Audit Log to reconstruct exactly what a user did during a specific session

Filters

Currently, the Activity panel supports the ALL filter, alongside the standard sort, search, and export controls in the top-right of the panel.

How this differs from the other two surfaces

Logging Overview

See how this fits with the other two logging surfaces

Audit Log

Drill into the individual events that make up a session

Asset Audit

See a curated, business-readable audit trail for a single asset