> ## Documentation Index
> Fetch the complete documentation index at: https://docs.get-hive.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit log: receipts for every action, and undo

> The Hive audit log records every action from signal to plan to decision to result, with before and after state. Learn how to read a receipt and undo reversible actions.

Every action Hive takes — or prepares and a person approves — leaves a **receipt**. The **Audit log** collects
them. Its own description is the contract: "Immutable. Every action traces signal → plan → decision → result. This
is the 'why' and the receipt."

## Open the audit log

The audit log is not pinned to the sidebar. Open it directly at
[app.get-hive.ai/audit](https://app.get-hive.ai/audit), or follow a link to a receipt from the place the action
started (for example, a handled signal).

Use the filter at the top to switch between **All actions** and **Reversible only**.

## What a receipt contains

| Field | What it records |
| - | - |
| **Actor** | Who or what made the decision — a named person, or Hive acting under a granted autonomy rung. |
| **Action** | What was done, in plain words. |
| **Tier** | The blast radius, **B0** to **B4**. See [Autonomy and blast radius](/approvals/autonomy-and-blast-radius). |
| **Chain** | The **Signal** that started it, the **Plan** Hive made, and the **Decision** that allowed it. |
| **Before / After** | The state of the affected record before and after the action. |
| **Reversible** | Whether the action can be undone, and whether it already has been. |
| **Department and time** | Which department it belongs to and when it happened. |

Receipts are written once and not edited. Undoing an action does not delete its receipt; it marks it as undone
and records the compensating action.

## "Why I did that"

Open a receipt's explanation to see Hive's reasoning in four steps:

<Steps>
  <Step title="What I noticed">The originating signal.</Step>
  <Step title="What I checked">The evidence and readings Hive looked at.</Step>
  <Step title="How I decided">The policy decision — which rung, which limits, who approved.</Step>
  <Step title="What I did">The action and its result.</Step>
</Steps>

The explanation ends with either **Reversible · one-click undo** or **Final · no compensating step**, so you know
straight away whether a mistake can be walked back.

## Undo an action

For a reversible action, expand the receipt and choose **One-click undo (replays compensating action)**. Hive runs the compensating action on the server (for example, restoring
the previous value or moving an item back) and marks the original receipt as undone.

* Undo needs the **Operator** role or higher.
* Undo is only offered when the source system can safely reverse the change. Irreversible actions — refunds,
  charges, deletions, revoked access — cannot be undone from Hive, which is why the policy engine always asks a
  person before running them.
* If an undo cannot be completed, Hive tells you why rather than marking the receipt undone.

## Use the audit log in an incident

If something went wrong:

<Steps>
  <Step title="Stop further actions">
    An Owner or Admin engages the **Kill switch** — see [Safety and control](/admin/safety-and-control).
  </Step>

  <Step title="Find the receipts">
    Filter to **Reversible only** to see what can be walked back first.
  </Step>

  <Step title="Trace the chain">
    Choose **Why did you do that?** on the receipt to see whether the cause was the source data, a learned rule, a policy setting or the
    connection.
  </Step>

  <Step title="Undo and correct">
    Undo what can be undone, then fix the cause: correct the source data, pause the rule in
    [Learned behaviours](/brain/learned-behaviours), or lower the action type's rung.
  </Step>

  <Step title="Resume deliberately">
    Resume autonomy only when the owner of the affected work confirms the fix.
  </Step>
</Steps>

## Related

<CardGroup cols={2}>
  <Card title="Review and approve" icon="circle-check" href="/approvals/review-and-approve">
    How actions get approved in the first place.
  </Card>

  <Card title="Safety and control" icon="shield-halved" href="/admin/safety-and-control">
    Kill switch and policy.
  </Card>
</CardGroup>
