Activity log
Activity records what people and NoCert did in your organization: who added a domain, who changed a rule, when a certificate was first seen, what was sent and to whom.
Operators and owners can read it. Viewers cannot.
What is in it
Section titled “What is in it”Actions taken by people: domains added, verified and removed, Sentinels enrolled and deleted, rules and targets created and changed, members added and their roles changed, policies and billing changed.
Things NoCert did on your behalf: certificates discovered and first seen on an endpoint, alerts sent. An alert entry names the certificates in the digest, the channel it went to, and any recipient that failed. Scans and enumerations are deliberately absent, since they run constantly and would bury everything else; the dashboard’s live feed is where you watch those.
Narrow the log with the All events and Changes toggle, the category filter (Configuration, Sentinel, Member, Notification, Discovery, Billing) or the search box. Changes drops the discovery category entirely, which is the quickest way to see only what people did. The discovery category is what the dashboard links into.
Times are UTC
Section titled “Times are UTC”Rows show relative ages. Hover one for the exact instant, given in UTC with your local time beside it.
Retention
Section titled “Retention”Entries are kept for 12 months, then deleted. The window is the same on every plan and cannot be extended.
Paging stops after 10,000 rows, which a year of history on a busy organization reaches. Narrow with a date range to read further back.
There is no export. If you need to keep audit history beyond a year, or hand it to an auditor in bulk, tell us what you need before you rely on the log for it.
Do not confuse this with the live scan feed on the dashboard. That one shows what is running right now and keeps nothing.