Skip to main content
The activity log answers the question the console could not answer before it existed: who removed that approved value, who edited that link’s destination, who made that person an administrator, and when. Open it from Activity in the navigation, or at app.utmkit.co/activity.

Written with the change, never after it

An entry is written inside the same operation as the change: if the entry cannot be recorded, the change does not happen either. There are therefore no gaps — a change that succeeded has an entry, and a change that was refused (by a rule, by a role, by validation) has none. Reads leave no trace: opening pages, running reports and exporting, the log itself included, record nothing. Entries cannot be edited or deleted by anyone, in any role.

What is recorded

Every successful change to the workspace’s links (created, edited, deleted, withdrawn, republished, expired, and a destination going unreachable or recovering), tags and saved views, the convention, approved values and dependency rules, members (added, role changed, parameter locks changed, removed), invitations (sent, revoked, accepted, bounced), the workspace’s two-factor requirement, broken-destination digests, and report schedules. Each entry carries:
  • Who — the person, by the email they had at the time. A change made through an API token names the person and the token. A change made by UTMKit’s own scheduled jobs (the abuse rescan, for instance) is attributed to System and the job’s name. The assistant is never the actor: the person who sent the message is.
  • How — from the console, the chat, the API or the MCP server.
  • What — the action, and the thing it targeted by the name it had at the time. If the target still exists the entry links to it; if it has since been deleted the name is kept.
  • The difference — for edits, the fields that changed with their previous and new values. Secrets, hashed values and uploaded files are shown as “changed” without their value.

Per-workspace and organization-wide entries

Most entries belong to one workspace and are visible only there. Custom domains, QR code designs and branding are shared by every workspace of the organization, so a change to one of them is recorded once, marked organization-wide, and shown in every workspace’s log: two administrators running two client workspaces see the same domain removal.

Who can read it

Owners and administrators. Members and viewers are not offered the page and are refused if they open it directly, because the log lists what every person in the workspace did, the owner included.

Finding an entry

The page lists entries newest first and can be narrowed by who acted, what kind of action it was, what kind of thing was targeted, and a date range, in any combination. The count of matching entries is shown, and Older entries pages back without repeating or skipping anything. Export CSV downloads every entry matching the current filters, newest first, one per row — not just the page on screen — with the difference flattened into columns a spreadsheet can read.
How far back the log reaches follows your plan’s retention window, the same window the analytics reports use; the page states it at the top. Nothing is deleted when a plan changes — a plan with a longer window reveals what was always there. The windows per plan are on the plans page.