How do I use the audit log and SSO settings?
Updated September 14, 2026 · 3 min read
Open Settings → Audit log to see who did what, when, and from which IP address. You need the Admin or Owner role. Filter by event type, resource and date range; on the Business plan you can also download the results with Export CSV. Sign-in rules for a whole email domain live next door, under Settings → Identity & SSO.
How do I read the audit log?
Events are listed newest first, 50 to a page, in six columns.
| Column | What it shows |
|---|---|
| When | Date and time in your own timezone |
| Action | The event verb, for example member.added or invite.revoked |
| Resource | What was acted on — the type, plus a short id |
| Actor | A short user id, or api-key when an API key did it, or system |
| IP | The address the request came from |
| Status | success or failure — failed attempts are recorded too |
How far back the log reaches is set by your plan: 7 days on the trial and Starter, 90 days on Pro, 365 days on Business.
How do I filter and export events?
The filter row across the top takes four inputs and a Reset filters button.
- Action — a dropdown of event families: Member events, Invite events, Ownership transfer, Auth / 2FA events, SSO config events, Workspace events, SCIM events, SAML events, API key events, Org settings events.
- Resource type — free text, for example
member,inviteorqr_code. - From and To — a date and time range.
On the Business plan an Export CSV button sits in the page header and downloads everything matching your date range, including the event metadata. On other plans the button is hidden, and the API answers "CSV export is available on Business+ plans".
The Action dropdown lists more families than are currently written to the log. QR code creation and edits, and ordinary sign-ins, are not recorded yet — filtering for them returns nothing rather than an error.
What gets recorded?
The log covers the privileged actions an administrator would be asked about in a security review:
- Members added, re-roled and removed, and ownership transfers
- Invites created, revoked and accepted
- Workspaces created, renamed and deleted
- Two-factor turned on or off, and backup codes regenerated
- Single sign-on and SCIM configuration changes
- API keys created
- Organization settings changes
How do I set up single sign-on for my domain?
Go to Settings → Identity & SSO and stay on the Single Sign-On tab. Google Workspace is the provider that is live today: people whose email matches your domains sign in with the Google button on the sign-in page, and an account is created for them on first sign-in.
- Allowed email domains — comma-separated, for example
acme.com, eu.acme.com. Anyone signing in with a matching address is routed into your organization. - Default role for new users — Admin, Editor or Viewer. Viewer is the safe default.
- Active — leave it ticked to switch the configuration on.
- Enforce SSO (block password login) — see the warning below before you tick this.
- Click Enable, or Save changes if you are editing. Remove deletes the configuration.
Enforce SSO blocks password sign-in for every address on the listed domains, and it applies to people who already have accounts. Only turn it on for Google Workspace, and only after confirming everyone on those domains can sign in with the Google button — including yourself. Turning it on for a provider you are not actually signing in with will lock the whole domain out.
People who hit the block see "Your organization requires SSO login". Every change here is logged under SSO config events.
How do I connect SCIM provisioning?
The second tab issues SCIM 2.0 tokens, so your identity provider can create, update and deactivate accounts instead of you inviting people by hand.
- Under SCIM 2.0 provisioning tokens, name the token after where it will live.
- Click Create token.
- Copy the token immediately and paste it into your provider's SCIM configuration. It is displayed once and cannot be retrieved afterwards.
- Use
https://qrcodestack.com/scim/v2as the SCIM base URL.
Existing tokens are listed with their prefix and last-used date, each with a Revoke button. SAML sign-in is available on request — email support@qrcodestack.com and we will set it up with you.
Common problems
The Audit log page shows an error
Reading it needs the Admin or Owner role. Editors and viewers cannot open it. Check the Your role badge at the top of Settings → Team.
"CSV export requires Business plan or higher"
Viewing and filtering the log works on every plan; only the CSV download is on Business. See plans and limits.
Someone on my domain cannot sign in any more
Check whether Enforce SSO is on: it blocks every sign-in route other than the enforced provider for that domain. Untick it, click Save changes, and ask them to try again — or have them use the Google button. More in changing or resetting your password.
Frequently asked questions
Who can see the audit log?
Organization admins and the owner. Editors and viewers have no access to it.
Can I download the log?
Yes, with Export CSV on the Business plan. It exports everything in your selected date range.
Are QR code edits recorded?
Not yet. The log currently covers members, invites, workspaces, two-factor, SSO, SCIM, API keys and org settings.
What does Enforce SSO actually do?
It blocks password sign-in for every address on the listed domains, so those people can only get in through the enforced provider.
Do you support SAML?
It is available on request — email support@qrcodestack.com. SCIM 2.0 provisioning is self-serve from the Identity & SSO page.
Related articles
How do I invite teammates and set their roles?
Settings → Team, enter an email, pick Admin, Editor or Viewer and click Send invite. The link expires in 7 days. Business includes 5 seats; other plans have 1.
How do I turn on two-factor authentication?
Settings → Security → Enable 2FA. Scan the QR code with an authenticator app, enter the 6-digit code, then save the 10 backup codes shown once.
What are workspaces, and when should I use them?
Workspaces split an organization into buckets — one per brand, region or client — each with its own roles. Business plan; only org admins can create them.
How do I change or reset my password, and which sign-in methods exist?
Signed out: click Forgot password? on the sign-in page — the emailed link lasts one hour. Signed in: Settings → Profile → Change Password.
Still stuck?
Email support@qrcodestack.com with the email on your account and, if it is about one code, its name or short link. A person replies within one business day, usually sooner.