Audit logs
See who created, changed or deleted which record and when — and use it for GDPR accountability.
2 min read
A patient record was deleted, an opportunity's value changed, or a user's permissions were widened — who did it? Audit Logs keep a record of important actions in the panel with the user, the date and the before/after values. Use them both to solve day-to-day problems and to meet your accountability obligations under GDPR (and KVKK in Turkey).
Before you start
- Only users with the Admin role can see the audit logs.
- Log entries are read-only; users can't edit or delete them.
- How far back the logs go may vary by plan. When you find an event you need to keep long-term, note the details or save a screenshot.
Review the logs
- Open Settings → Audit Logs.
- Narrow your search with the filters at the top:
- Date range: e.g. last 7 days
- User: who performed the action
- Module: Contact, Opportunity, User, Calendar and so on
- Action: Created, Updated, Deleted
- Click the eye icon on a row to open its details.
The details panel
The details panel shows the user, the date and time, and the before and after value of every changed field. In the example above, Mehmet Demir moved Sarah Mitchell's opportunity from "Consultation" to "Deposit Paid", raised its value from €3,200 to €4,800 and made himself the owner.
Common scenarios
A patient record has disappeared. Filter on Module: Contact, Action: Deleted. You'll see who deleted it and when. To restore a deleted record, message our support team on WhatsApp; whether it's possible depends on when it was deleted.
An opportunity moved to another rep. Filter on Module: Opportunity to find it, and see who changed the Owner field. It's a neutral source of truth in commission disputes.
A user's permissions changed. Filter on Module: User to track permission changes. An unexpected increase in permissions is a warning sign for your account security.
Using audit logs for GDPR and KVKK
Clinics that treat patients from Europe must be able to show who processed health data and why. Audit logs help with this:
- Access tracking: shows who made changes to patient data.
- Erasure requests: when a patient asks for their data to be deleted, you can show that the deletion was carried out, with date and user.
- Incident review: if there's a suspicious bulk deletion or change, you can quickly find which user it came from.
Important
Audit logs are only meaningful if every staff member has their own user. If several people share a "clinic@" account, the logs can't show who did what. MedicalGrow includes unlimited users — give everyone a separate account (Add users to your team).
Note
Audit logs alone don't make you GDPR/KVKK compliant; obligations such as explicit consent, privacy notices and a data retention policy remain your clinic's responsibility. More: Data privacy.
Related articles

Didn't solve your problem?
Ask the assistant or message our support team.