audit trail for user management changes
There should be an audit trail/logs for user and role management, so that super admins at the very least can track who added users - this is a major security concern that we cannot see this
We have recently had an external email address user added as a super admin, yet no-one internally knows who added this or why - concerning
-
Hi, thank you for raising this — it's a completely valid concern and we take security visibility seriously.
Good news: this capability already exists in Admin Center today. Under Settings → Usage & Billing, there is an Opti ID User Activity Log that captures exactly what you're looking for — including who added or removed users, what was changed, when it happened, and whether the action was performed by a human admin or the system. So if an unknown external email was added as a Super Admin, that action would appear in this log with the actor's details.
You can also download the log in multiple formats (CSV, Excel, HTML etc.) by clicking the three-dot menu in the top right corner of the table, making it easy to share or audit offline.
This feature is currently tucked away under Usage & Billing, which isn't the most intuitive place to look when you're investigating a security concern. That's something we're looking at improving so it's easier to find.
In the meantime, we'd recommend bookmarking that page and using the filters to narrow down by event action (e.g. 'added') and date range whenever you need to investigate a specific change.
Thanks again for taking the time to share this — it directly helps us prioritize where to improve.