Who Read What, and When
Every read of a document is recorded — and so is every refusal, which is often the more interesting event.
Where to find it
Architect Panel → Security → Document Access for the report across the whole library. On a record, the Access panel of the Documents pane shows one document’s history to administrators.
What is recorded
The document and version, who (or what — a person, a link, an emailed key), when, from which address, and the outcome. A refusal keeps the reason.
Documents, not files
A deliberate line. An upload that belongs to no document writes nothing, so the thousands of avatars, logos and inline images the platform serves are not logged.
A file access log is a different feature with a different volume and a different privacy footprint, and it should be decided on its own merits rather than arrived at by accident.
Refusals are the point
Somebody reaching repeatedly for a document they may not have is exactly what a log is for, and one that recorded only successes could not show it.
“Access granted” is not “opened”
The honest limit, and it is stated in the interface as well as here. Where files are held in S3, the platform authorises the read and hands the browser a short-lived URL; the bytes then move browser-to-bucket without passing through the platform again.
So the row means access was granted. The read follows within a few minutes in practice, and the URL is deliberately short-lived for exactly that reason — but the log does not claim to have watched it happen.
Nobody can clear it
There is deliberately no button anywhere that wipes the log. A record somebody can erase on a bad afternoon answers no question anybody would trust it to answer.
What there is, is a configurable keep window that the housekeeping task prunes to. It defaults to keeping everything, because losing the record of who read what is not a thing to do by accident.
Worked example
A complaint alleges a report was shared inappropriately. The access log shows four reads: three caseworkers on the case and one refusal from somebody who was not. The refusal is the answer — nothing leaked — and it took one screen.
Recommendations
- Leave the keep window at everything unless you have a reason and a policy.
- Look at refusals, not only reads.
- Say "granted" rather than "viewed" when you quote it to anybody.
- Pair it with the Sharing panel: one says who did, the other says who could.