Features
Audit Log
Vextro automatically logs admin actions to the adminAuditLog table. Document mutations, access control changes, bulk operations, and template management all generate audit entries without configuration.
Logged actions
Document CRUD
| Action | When |
|---|---|
document.create | A document is created |
document.update | A document is updated (only if fields changed) |
document.delete | A document is deleted |
document.duplicate | A document is duplicated |
global.update | A global document is updated |
Access control
| Action | When |
|---|---|
access.user.status_changed | A user's status is changed (active/inactive/pending) |
access.role.created | A new role is created |
access.role.deleted | A role is deleted |
access.role.assigned | A role is assigned to a user |
access.role.removed | A role is removed from a user |
access.permission.granted | A permission is added to a role |
access.permission.revoked | A permission is removed from a role |
access.scope.assigned | A scope is assigned to a user |
access.scope.removed | A scope is removed from a user |
Bulk operations
| Action | When |
|---|---|
bulk.status | Bulk status update |
bulk.delete | Bulk delete |
bulk.tags | Bulk tag update |
bulk.import | Bulk document import |
Templates
| Action | When |
|---|---|
template.create | A template is created |
template.update | A template is updated |
template.delete | A template is deleted |
Entry shape
Each audit log entry has the following shape:
| Field | Type | Description |
|---|---|---|
action | string | Dot-delimited action identifier |
collectionSlug | string? | The collection this event relates to |
documentId | string? | The document or user ID this event relates to |
userId | string? | The acting user's ID |
userEmail | string? | The acting user's email |
userName | string? | The acting user's display name |
details | object? | Action-specific metadata (e.g. changed fields, previous status) |
createdAt | number | Timestamp of the event |
Custom audit logging
Use the logAuditEntry utility to write audit entries from custom Convex mutations:
import { logAuditEntry } from "vextro/convex/audit";
export const archiveProject = mutation({
args: { projectId: v.id("projects") },
handler: async (ctx, args) => {
await ctx.db.patch(args.projectId, { status: "archived" });
await logAuditEntry(ctx, components, {
action: "project.archived",
collectionSlug: "projects",
documentId: args.projectId,
userId: "user123",
details: { reason: "quarterly cleanup" },
});
},
}); The utility is also re-exported from vextro/convex/admin:
import { logAuditEntry } from "vextro/convex/admin";
logAuditEntry is fire-and-forget. If the underlying write fails, the error is silently swallowed so that audit logging never blocks the primary mutation.
Viewing the audit log
The audit log is available in the admin UI at /settings/audit-log. It supports filtering by action, collection, user, and date range.
Programmatically, use the listAuditLog and getDocumentAuditLog queries generated by the admin module to read audit entries.