What information is available in the Change Log?

The screenshots in this article show the German interface. Where a button or field matters, the German label is given in brackets so you can match text to screenshot.


ContractHero records changes continuously, on two separate levels: permission changes across your organisation, and changes to each individual contract. This article shows what each log contains and where to find it.


What's in it for you


The change log turns "who did that again?" into a question with a clear answer — date, person, action, detail. It cuts the effort of an audit dramatically (one look into the system instead of Excel lists and email searches), it helps you meet requirements from GDPR, ISO 27001 or internal compliance policies, and it creates a culture in which every change is traceable. ContractHero logs continuously — there is nothing for you to switch on or maintain.


Two levels: organisation and contract


There is no single master log in ContractHero. Instead there are two separate views — deliberately, because the content differs and each requires different permissions:


  • Change log for permissions („Änderungsprotokoll für Berechtigungen", organisation level) — Settings → Change log („Einstellungen → Änderungsprotokoll"). This is where you see all permission, role and member changes in your organisation.
  • Contract change log („Vertragsänderungsprotokoll", contract level) — per contract, in the "Activity" tab („Aktivität"). This is where you see all changes to that specific contract: creation (including via email import), field values, documents, status and links.


How it works


1. Open the organisation-wide permissions log


Go to Settings („Einstellungen").





Then go to Change log („Änderungsprotokoll").





You will see the "Change log for permissions" page („Änderungsprotokoll für Berechtigungen") with the subtitle "Change log for tracking user access and security updates". The table has three columns:


  • WHEN („WANN") — date and time of the action (e.g. "15.05.2026 11:36").
  • WHO („WER") — the person who performed it (e.g. "Joshua Smith (you)"). For system-side lifecycle events (e.g. "Logging started", „Protokollierung gestartet") this column shows a dash ("—").
  • ACTION („AKTION") — what happened: invitations sent, roles created, category access changed, a member's role switched — each with category chips and the detail information directly in the cell.


The list is sorted chronologically, newest first. Where there are many entries, you can click "Show details" („Details anzeigen") on an entry to expand the full record.


2. What appears in the organisation log


The permissions log focuses strictly on identity and access changes:


  • Invitations sent / accepted
  • Members added or removed
  • Roles created, changed, deleted
  • Role assignments to members
  • Owner status granted or removed
  • Category access changed per role
  • Team assignments


What does NOT appear here: specific changes to individual contracts (field values, status, documents). The contract change log covers those (step 3).


3. Open the contract change log on a contract


Open any contract. In the tab column on the right you will see a speech-bubble icon labelled "Activity" („Aktivität") — right at the bottom of the column, below Documents, Summary, Tasks, Signature, Approval and Linked („Dokumente, Zusammenfassung, Aufgaben, Signatur, Freigabe, Verknüpft").


Click "Activity" („Aktivität"). The sidebar switches to the contract change log („Vertragsänderungsprotokoll") listing every action on this contract in chronological order, newest first.


Example entries:


  • "Max Musterman (you) edited the contract — 11.05.2026 21:56" plus "Show details" („Details anzeigen")
  • "Max Musterman (you) added a document — 11.05.2026 21:56"
  • "Contract created" („Vertrag erstellt")
  • "uploaded via email import from — 11.05.2026 21:56" (for contracts that arrived through the team import address)


Click "Show details" („Details anzeigen") under an entry to see which field was changed and to which value.







Common questions


Can I see the permissions log as a regular member?
No. The area is reserved for owners and members with admin rights.


How far back does the log go?
Recording starts with the entry "Logging started" („Protokollierung gestartet") on a specific date, which is visible in the permissions log. Actions before that date are not captured — for long-standing accounts this often corresponds to the point at which the audit log function was activated for your organisation.


Can I delete or edit entries in the log?
No. That is deliberate — an audit log that could be changed afterwards would be worthless. Even owners cannot remove entries.


Can I see whether a contract was imported by email?
Yes. In the contract change log (the Activity tab on the contract), contracts delivered by email carry an entry reading "uploaded via email import", including the sender address. So you can see after the fact which mailbox the contract came from — useful when following up with a supplier or handing over material for an audit.


Can I export the log?
There is currently no one-click export. For audit handovers, a screenshot or a screen recording of the relevant period is the practical route. If you need more than that (e.g. for a SOC 2 audit), please contact support — certain data can be provided in structured form on request.


Can I see who downloaded a file?
Read and download events are not currently logged consistently in the contract change log. The log focuses on write access (creation, change, deletion). If you need this information for compliance, please contact support.


Where do I find the comment function?
In the contract change log (the Activity tab on the contract), right at the bottom. The organisation-level permissions log has no comment function.


What happens to the log when a contract is deleted?
That depends on the type of deletion: in the recycle bin (soft delete) the contract's activity log is retained and is restored together with the contract. On permanent deletion, the contract log is deleted with it — the organisation-level permission logs, however, remain untouched.


Good to know


  • Two logs, two purposes. Do not mix the two up. For "who revoked Lisa's access to the NDA category?" → permissions log. For "who changed the end date on lease agreement XY?" → contract change log on the contract.
  • Email import is visible in the log. Contracts delivered through the team import address carry the sender address as context in the contract change log — useful when following up with suppliers or handing over material for an audit.
  • "Activity", not a clock icon. The UI has changed the icon over time — today it is a speech-bubble icon labelled "Activity" („Aktivität"). If older internal notes still refer to a "clock icon", that is out of date.
  • Comments are not the log. Comments you leave in a contract's Activity tab are saved and visible, but they are not system-side audit entries. For legally sound evidence, what counts is the automatic log entry, not the manual comment.
  • Take a pragmatic approach to audit prep. Before an audit, a dry run pays off: open the permissions log, work through the last quarter, identify anything that stands out (e.g. "full access to all categories" for people who do not need it) and correct it — before the auditor asks.
  • Understanding "Logging started". For older accounts the log often begins not on the organisation's day one, but on the day the audit log was activated. If your account existed before that date, there is a deliberate gap — not a bug.



Updated on: 08/26/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!