HomeFeaturesRecords

Records

Who did what, and what it used to say.

A team of four sharing an inbox needs this the first time two people disagree about who deleted a campaign. The Logs page under Workspace answers that, and a harder question too: what did it say before.

17 areas
of recorded activity
Before + after
on every edit
180 days
kept, then cleared automatically

What you get

A workspace-wide record of every change anybody made — with the old value beside the new one, and no way for anybody to tidy it.

Every change, recorded

Campaigns, contacts, templates, files, tasks, settings, sign-ins. Seventeen areas of activity, filterable to one of them or one person.

The old value, kept

“Profile updated” answers nothing. “Time zone was Europe/London, now Asia/Tokyo” explains why that person’s campaigns moved.

Nothing can erase it

There is no delete button, and none for you either. A record somebody can remove their own line from is not a record.

Names that survive

The log keeps who somebody was and what a thing was called at the time — so “who deleted Summer Sale” still reads after it is gone.

Refused sign-ins too

Five wrong passwords in a minute is the entry that matters most, and the one a rate limiter otherwise handles completely silently.

What the system did alone

Automatic acts — a campaign cancelled for missing its hour — are attributed to Birsend, never to whoever happened to create it.

How it works

01

Append-only, and it means it

There is no route that edits or deletes an entry — not in the panel, not in the API, not for the owner. Entries leave on age alone, by a rule applied to everything equally. Letting somebody remove one line is letting them remove the line about themselves.

  • Nothing is written when nothing changed: a save that alters no value leaves no entry
  • Reading it is a narrow permission. It shows every colleague’s actions with times and addresses, which is not something everybody needs
  • Entries older than 180 days are cleared nightly, and the page says so rather than leaving you wondering
02

Written to survive the thing it describes

The name of the person and the name of the record are copied onto the entry as they read at the time. A log that only holds references becomes a list of “somebody deleted #418” the moment the row is gone.

  • A colleague who has since left still has their name on their entries
  • A campaign renamed afterwards keeps its old name on the old entry — which is the true statement about that moment
  • Passwords and API secrets are never stored. A password change is recorded as having happened, never with the value
03

The entries nobody expects to need

A refused sign-in is separated by reason: wrong password, locked out after five attempts, or a correct password against a suspended account. The last one means somebody holds working credentials, which is a different problem entirely.

  • The sign-in screen still refuses a wrong password and an unknown address identically — that reasoning is about what goes back over the wire
  • Deleting a message stores the text, because the message itself is gone and “somebody deleted a message” raises the question it was written to settle
  • Automatic acts are attributed to Birsend rather than to a person, because attributing them to somebody would be a lie that reads as fact

What it does not do

The honest list. We would rather you found this here than three weeks into a trial.

  • It records actions, not reads. Who opened a contact is not tracked.
  • Entries are kept for 180 days. If you need them for longer, export or say so — it is one setting.
  • The log is per workspace, so a refused sign-in against an address that belongs to nobody is not recorded here.

Questions

Can an admin delete an entry about themselves?

No. There is no delete route at all. The only thing that removes entries is age, and that applies to every entry equally.

Does it store message contents?

Only where the original is gone. A sent message is recorded as sent and the body stays on the message; a deleted message keeps its text in the log, because otherwise the entry cannot answer what was removed.

Cookies

The site runs what it needs to work, including the Crisp chat bubble. Google Analytics is the one thing we will not load unless you agree to it.