← All Field Notes
GHL · Digital Marketing Agency · Oct 2, 2026

The Audit Log Was Empty, And That Proved Nothing About Who Had Looked

The Audit Log Was Empty, And That Proved Nothing About Who Had Looked

Key takeaways

Most of what we set up as a Go High Level San Jose shop ends up holding sensitive stuff. Customer phone numbers. Text conversations. Notes from sales calls. Payment history. So when an owner asks "who can see all this," that's a fair question, and it deserves a real answer.

In August we needed that answer for one account, and the first place we looked gave us a very confident wrong one.

The obvious place to look

The CRM we build on has an audit log. It's in the settings, it has filters for user, module, action and time range, and it lists what happened in the account and who did it. If you want to know whether someone has been in your data, that's where you'd go.

So we pulled it for the window we cared about and went looking for any sign that someone had been in the data.

Nothing that answered the question. No entries showing anyone reading conversations or opening contacts.

It would have been easy to stop there and say nobody looked. That reading is wrong.

Diagram of what the audit log records and what it does not: creates, updates and deletes are logged, while logins, opening a contact and reading a conversation leave no entry

What the log actually records

We went back and read the documentation properly. The audit log records changes. Something created, something updated, something deleted. That's the whole list.

It doesn't record logins. It doesn't record someone opening a contact. It doesn't record someone scrolling through a text conversation, reading call notes, or looking at payment records. Someone with admin access could sign in, read everything in the account and sign out, and the log would look exactly like a quiet day.

So an empty log isn't evidence that nobody looked. It's evidence that nobody changed anything. Those are very different claims, and only one of them was the question.

The retention number was wrong too

The help page for the audit log says it keeps 60 days of history. If you believed that, you'd assume anything older was gone and stop digging.

Our live pull returned entries going back more than a year. So the record covered a lot more time than the documentation said, and a lot less activity than people assume. Both were the opposite of what you'd guess from the settings screen.

We now treat what the documentation says a log keeps as a starting guess and check it with a real pull.

What it's actually good for

The log isn't useless. It answers a different question really well.

Filter it to the users module and you can see when a person was given access to the account, and who gave it to them. That's often the question that matters most. Not "did they look," which you can't prove either way from here, but "should they have been able to look at all, and who let them in."

From there the fix is boring and effective. Take access away from anyone who shouldn't have it, give everyone else the lowest level they need, and check the user list on a schedule instead of only when something feels off.

Checklist of what to do instead: use the log to see when access was granted and by whom, remove anyone who should not have access, give everyone else the lowest level they need, and review the user list on a schedule

The lesson we are keeping

An empty record feels like an all clear. Before you trust it, find out what the record was ever able to show. A camera pointed at the front door doesn't tell you nobody used the back door.

What this means for Go High Level San Jose businesses

Your customer data probably lives in more places than you think. Your CRM. Your website host. A shared drive with old quotes and invoices. An email account an employee who left still knows the password to.

For most of those, if someone quietly read everything, nothing would show it. That's normal for most tools you use. The only control that really works is deciding who can get in at all.

Three things worth doing this week:

Go High Level San Jose owners trust their CRM with every customer they have. Know who has the keys, because the log won't tell you who looked.

Want this built for you

We set up CRMs with access you can explain, user by user, and you own the account outright. Start at optechsol.llc.

Want this working in your business?
Get my plan ← Back to all Field Notes