Every important action on your site is recorded automatically, admin logins, failed login attempts, logouts, plugin and theme activations, and more. If something goes wrong, you'll have a full timeline of who did what and when, making it easy to spot suspicious activity or roll back unwanted changes.
WordPress doesn't keep a real audit trail by default. If a plugin disappears, a theme switches, or a user gains admin privileges, there's no built-in record of who triggered it. When you're running a multi-author site, an agency client portfolio, or simply want forensic clarity after an incident, that gap is a problem.
The Guardian Gaze audit log fills it. Every action that touches site state (logins, role changes, content publishes, plugin installs, settings edits) gets a timestamped, attributed entry. Search it, filter it, export it. When auditors, clients, or insurance carriers ask "what happened?", you have an answer.
Successful logins, failed login attempts (with IP), logouts, password resets, 2FA challenges.
New user registrations, role promotions or demotions, user deletions, profile edits.
Installations, activations, deactivations, deletions, updates, including who triggered each.
Changes to site title, URL, admin email, permalinks, and other critical wp_options values.
Posts published, edited, trashed; pages created; menu changes; widget configuration.
Scans run, threats quarantined, files approved, IPs blocked, hardening rules toggled.
The log isn't just a passive list. Filter by user, by IP, by event type, or by date range. Search for a specific plugin name and see every action involving it. Export to CSV for incident reports, compliance audits, or hand-off to a forensics team.
Every entry carries the user, IP address, user-agent, timestamp (in your site's timezone), and the affected object, so reconstructing a sequence of events takes minutes, not hours.
The audit log is included on every Guardian Gaze tier, including the free plugin.