Reading the audit log
Who changed what, when, and from where. The log is only useful if somebody looks at it.
What is recorded
Administrative actions: account creation and role changes, permission edits, ticket deletion, setting changes, export operations and login attempts — each with the account, timestamp and IP address.
A monthly ten-minute review
Look for logins outside working hours, permission grants you did not authorise, deletions of any kind, and exports of customer data. Four things, ten minutes, once a month.
When something goes wrong
The log answers “the system deleted it” claims definitively. Combined with backups it turns an argument into a restore.