Embedded B2B audit trails

WorkOS Audit Logs

A product-specific WorkOS service for emitting, organizing, exporting, and streaming organization-scoped audit events.

Editorial verdict

Choose WorkOS Audit Logs when a B2B product needs a deliberate customer-facing audit trail and the team will define a stable event taxonomy and verify retention, export, and streaming terms.12

Best for

  • Organization-scoped B2B audit trails
  • Customer exports and SIEM delivery
  • Teams prepared to own a stable audit-event schema
12

Not ideal for

  • General application debugging or infrastructure logs
  • Teams expecting the provider to infer complete audit events
  • Requirements for independently verified immutability or retention not covered by contract
12
Main trade-off

A managed tenant-facing audit product reduces storage and export implementation while coupling event schema, retention, streaming, access, and migration to WorkOS.12

Product boundary

Whether to build an application-owned audit trail on WorkOS rather than treat operational logs as a customer-facing audit record.

WorkOS Audit Logs is separate from AuthKit, SSO, Directory Sync, and the generic WorkOS platform. It stores application-emitted audit events; the application still owns event completeness, actor semantics, authorization, integrity at emission, and sensitive-data minimization.12

For: B2B software teams adding tenant-scoped audit events, exports, and optional SIEM delivery to their product

  • The product needs tamper-evidence or retention guarantees beyond current terms.
  • Customers require an unsupported SIEM destination or export path.
  • Operational logs rather than a tenant-facing audit trail are the actual need.

Why teams consider WorkOS Audit Logs

  • Audit event modelEvents include actor, action, targets, context, and organization scope.12
  • Customer accessExports and dashboard access support customer audit workflows.12
  • SIEM pathLog streaming can deliver events to supported destinations under separate commercial terms.12

Pricing

The public pricing surface separates stored event volume, retention, and SIEM connections; record current included usage, per-event storage, retention, connection count, and enterprise terms.2

Embedded audit trail

Base Audit Logs usage

Model emitted and stored event volume, included usage, retention, export behavior, and organization access.2

Log streaming

Per SIEM connection or enterprise terms

Model connection count, destination support, delivery behavior, and any enterprise contract requirements.2

Reviewed base
$0 per month on the public Audit Logs page2
Reviewed log streaming
$125 per month per SIEM connection2
Reviewed event retention
$99 per month per one million stored events2
Application duty
The product must emit complete and authorized events2
Pricing checked View official pricing

WorkOS Audit Logs vs alternatives

Axiom

Choose when
The leading job is flexible analysis of structured audit-event data rather than a built-in tenant audit product.
Avoid when
Customer-facing exports and embedded organization audit UX should be supplied as a product feature.
Compared with WorkOS Audit Logs
Event analytics flexibility replaces the dedicated B2B audit surface.3

Datadog

Choose when
Audit events must join a broader enterprise logging and security-operations platform.
Avoid when
The organization cannot govern log ingest, indexing, retention, access, and suite cost.
Compared with WorkOS Audit Logs
Enterprise log breadth replaces a focused embedded audit product.4

Resources and sources

Official product, policy, and pricing

  • WorkOS Audit Logs documentation
    Open
  • WorkOS Audit Logs
    Open

Related tools

Related tasks

  1. 1
    WorkOS Audit Logs documentation

    WorkOS · Accessed Official

  2. 2
    WorkOS Audit Logs

    WorkOS · Accessed Official

  3. 3
    Axiom documentation

    Axiom · Accessed Official

  4. 4
    Datadog Log Management

    Datadog · Accessed Official