All modules

Audit Logs

A tamper-proof record of every change made in the HRMS — who did it, when, from where, and exactly what changed — with a safe undo for each action.

Overview

Audit Logs records every change to the organization's data automatically: an employee edited, a leave approved, a salary structure changed, a payroll run finalised, a role's permissions edited, a job candidate moved. Each entry says who acted, when, from which IP address and device, which module it belongs to, which employees it affected, and shows the exact before-and-after values of every field.

It also records events that change nothing but matter for security and compliance: sign-ins and failed sign-ins, exports and downloads, and views of sensitive information such as salaries, bank details and payslips.

Most data changes can be undone from here, with a reason. The undo restores the old values (or re-creates deleted records together with their dependent rows), is itself recorded, and can be undone again. The log is chained with a cryptographic hash, so any later tampering with past entries is detected by the "Verify integrity" check.

Who uses it

  • Super Admin: The only role that can open Audit Logs. Reviews and filters all activity, opens entries to see the full detail, undoes actions, exports the log, configures retention and the undo window, and runs the integrity check. Also sees a History tab on every employee's profile.
  • Employees and other staff: Do not see Audit Logs. When an action affecting them is undone, the affected employee (and the person who originally made the change) receives an in-app notification with the reason.

What you can do here

See what happened

  • The Activity tab opens with a summary: actions today, the last 7 days, failed sign-ins in the last 7 days, undos in the last 30 days, a chart of actions per day and the busiest modules.
  • Every entry is written as a plain sentence (for example "Ayesha Khan approved Bilal's annual leave for 3 days"), with the time, the module, the affected employees, how many records changed and an undo status (Revertible, Not revertible, Reverted or Undo expired).
  • Open an entry to see the detail drawer: each changed record with a Before / After (or Created / Deleted) comparison, the recorded request details (IP address, device, page), and the undo history of that entry.
  • Actions performed by the Workyla platform team while signed in as a user are marked "Impersonated by …".

Filter, save and export

  • Filter by date range (today, 7 / 30 / 90 days, all time or a custom range), Performed by, Affected employee, Module, Action type, Department, Designation and Status.
  • Tick "Include system actions" to also see automatic jobs (accruals, reminders, scheduled changes); they are hidden by default. Tick "Impersonated sessions only" to review platform support sessions.
  • Save any combination of filters as a named preset (for example "Payroll changes this month") and re-apply it in one click.
  • Export exactly what the filters show to CSV or Excel. The export itself is recorded in the log.
  • Page through results 25, 50 or 100 at a time.

Undo safely

  • Undo one entry from its drawer, or tick several entries and choose "Undo selected". A reason of at least 5 characters is required; it is shown in the log and to the affected employees.
  • Before anything changes, the undo dialog shows what will happen to each record: will get its old values back, will be restored (it was deleted), or will be removed (it was created).
  • If a field has been changed again since the entry, the dialog shows a conflict for that field and you choose per field: "Keep current" or "Restore old".
  • An undo can be undone again ("Undo this undo"), so a mistaken undo is never permanent.
  • Sign-ins, exports, emails and similar events are recorded but cannot be undone. Actions older than the undo window show "Undo expired".
  • Anything that would change a payroll month that is already approved or paid is blocked, with an explanation — correct it through payroll instead.

Settings & integrity

  • Choose how long audit entries are kept: 1, 2, 5 or 7 years, or keep forever (the default). Shortening it asks for confirmation, because older entries are then permanently deleted.
  • Choose the undo window in days (default 90). It cannot be longer than the retention period; older entries stay in the log but can no longer be undone.
  • Click "Verify integrity" to recheck the hash chain of the whole log. The result is either "No tampering detected" or a list of the entries that do not match.

Step-by-step: Find a change and undo it

  1. 1Open Audit Logs from the sidebar (Super Admin only) and stay on the Activity tab.
  2. 2Narrow the list: pick a date range, then the Module (for example Leave) and, if you know them, the person who made the change under Performed by or the employee under Affected employee.
  3. 3Click the entry to open its detail drawer and check the Before / After values to confirm it is the change you are looking for.
  4. 4Click "Undo this action". Read what will happen to each record, and if a conflict is shown choose Keep current or Restore old for each field.
  5. 5Type the reason for the undo and confirm. The entry now shows Reverted, a new undo entry appears at the top of the log, and the affected employee and the original actor are notified.

Step-by-step: Review an employee's full history

For the Super Admin

  1. 1Open Employees and click the employee.
  2. 2Open the History tab on their profile — it lists every change that affected this employee, from any module.
  3. 3Open an entry to see its detail, or undo it from there exactly as in the main Audit Logs page.

Step-by-step: Export an audit report for an auditor

For the Super Admin

  1. 1Set the filters you need (for example Date range: Custom, Module: Payroll & Salary).
  2. 2Optional: click "Save preset" and name it so you can repeat the same report next month.
  3. 3Click CSV or Excel above the table. The file contains exactly the filtered entries, including who acted, what changed, IP address, device and undo status.

Step-by-step: Check that the log has not been tampered with

For the Super Admin

  1. 1Open Audit Logs › Settings & integrity.
  2. 2Click "Verify integrity" and wait for the check to finish.
  3. 3"No tampering detected" means every entry still matches the chain. If problems are listed, note the entry numbers and contact Workyla support.

How it connects to other modules

  • Every module: changes are captured automatically at the database level, so nothing done through the app escapes the log — including changes made by scheduled jobs (shown when "Include system actions" is ticked).
  • Employees: the History tab on each employee profile is this log filtered to that employee.
  • Payroll & Salary: undo is blocked for anything that would alter an approved or paid payroll month.
  • Notifications: undoing an action notifies the affected employee and the person who made the original change.
  • Recruitment and Performance: job, candidate, offer and performance-action changes are recorded under their own modules.

Good to know

  • Only the Super Admin can see or use Audit Logs; the permission cannot be granted to other roles.
  • Passwords, tokens and other secrets are never stored in the log — they appear as a hidden placeholder.
  • Deleting a record keeps a full snapshot of it (and of the records deleted with it) in the entry, which is what makes undoing a delete possible.
  • Undo is refused when it cannot be applied safely, for example when a restored record would clash with one created since. The dialog explains why.
  • Candidate emails sent by Recruitment and diversity-survey answers are deliberately not copied into the audit log: the first is already its own log, the second must never be linkable to a person.