Audit & Compliance

Know who did what, and prove it

Workspace events — membership changes, invitations, mailbox changes, security-relevant actions — are recorded as they happen, browsable with filters, and exportable as CSV for compliance reviews.

The problem

"Who removed that mailbox?" should not be a mystery

When several people administer shared mail, changes happen without a trace: a member removed, a role escalated, a mailbox disconnected. Without a record, every incident review starts with guesswork, and every compliance questionnaire gets an awkward answer.

The TELVRIX approach

Events recorded at the source

TELVRIX records workspace events server-side at the moment they occur — the same code path that performs the action writes the event. The activity page shows the trail with human-readable labels, actor resolution, and event-type filters.

For reviews and audits, both the member roster and the full event log export to CSV. Export access is itself role-gated: only owners and admins can read or export audit data.

Workflow

From action to evidence

  • 01

    Actions emit events

    Invitations, role changes, member removal, mailbox changes, and security actions write audit events server-side.

  • 02

    Browse the trail

    The workspace activity page lists events with actor email, event type, and timestamp — filterable by type.

  • 03

    Export for review

    Download members or the complete audit trail as CSV from the workspace or via the export API.

  • 04

    Retention by plan

    Message retention windows are plan-defined; audit access is limited to owner and admin roles.

Activity — Acme Support

Member role changed

dana@acme.com · lee → admin · 2h ago

roles

Invitation created

sam@acme.com · role: member · 1d ago

invites

Mailbox connected

dana@acme.com · support@acme.com · 3d ago

mailbox

Member removed

dana@acme.com · former contractor · 5d ago

members
Workspace activity log

Capabilities

What you get.

Append-only event log

Events are written by the action itself, not reconstructed after the fact.

Actor attribution

Every event records which user performed it; the UI resolves actors to email addresses.

Event-type filtering

Narrow the trail to invitations, role changes, mailbox events, or any recorded type.

CSV export

Members and audit events export to CSV with stable headers for spreadsheets and GRC tooling.

Role-gated access

Audit pages and the export API require the audit:read permission — owner and admin only.

Plan-gated tiers

Audit log on Business and Enterprise; compliance export on Enterprise.

AvailabilityThe audit log requires the Business plan or above; CSV compliance export requires Enterprise. Access is restricted to workspace owners and admins.

Put audit & compliance to work.

TELVRIX is in closed beta. Apply for access, or sign in if you already have an invite.