Skip to main content

Admin activity audits

In Liberator 2.5 and later, Liberator keeps an activity audit of administrative changes. It records who did what, when, and whether the change succeeded. Use it for access reviews and for questions that usage and entitlements reports do not answer, such as who granted access or what was deleted.
Reviewing another administrator’s activity is a Super Admin capability. The audit is separate from usage_log, which records dataset queries rather than admin changes.

Ask from Reporting

Open Reporting and ask in plain language, for example:
  • “Who gave this user access?”
  • “What changed last Tuesday?”
  • “What has this admin done this month?”
  • “Was anything deleted?”
  • “Show me failed attempts.”
Ask for a download when you want the matching rows in a file. You can also save that question as a template and schedule it, the same way as other Reporting queries.

What each entry contains

When you ask what a value changed from and to, the answer can include the before and after values. Passwords, API tokens, and similar secrets are omitted.

What the audit covers

Liberator records changes made through the admin portal, including:
  • Users, including create, update, enable, disable, and password or API-key actions
  • Entitlements and permissions
  • Datasets and connections
  • User groups and dataset groups
  • Webhooks and file uploads
  • Report templates and report schedules, including who a scheduled report is sent to
Changes made outside Liberator, such as edits in the identity provider’s own console, are not included. The audit starts when it was enabled for the environment, so an empty result for an older date means those changes were not recorded.

AI-based reporting

Run admin queries, save templates, and schedule email delivery

Query usage log

Per-query dataset usage, separate from admin changes

Managing users and entitlements

The user and access changes the audit records

What's new in 2.5

Liberator 2.5 release notes