Skip to content

Log Profiles & Audit Logging

4 min readUpdated: Sep 26, 2026
View as Markdown

The Log Profiles module delivers forensic security and compliance audit logging across the Switchboard subsystem. In regulated enterprise environments (e.g., healthcare, financial services, and customer care centers), administrators must maintain an immutable record of operator activities—particularly sensitive supervisory telephony actions such as silent eavesdropping, whisper coaching, and line barging.

Log Profiles define exactly which operational events (Create, Read, Update, Delete, and Action) are captured in the platform’s tamper-evident audit logs (ss_switchboard.audit_logs).

Log Profiles Management


Profile Name Status Intended Scope Logging Intensity
Default Profile Active / Default Standard operator workstation operations. Captures modifications, deletions, authentication events, and call transfers.
Supervisor Audit Active Supervisory, quality assurance, and managerial accounts. High-fidelity logging capturing every Spy, Whisper, Barge, and queue intervention.

When configuring a Log Profile, administrators enable specific audit triggers for each subsystem module:

Module Identifier Functional Area Key Audited Telephony & Management Events
auth Authentication Operator login, logout, session expiration, SSO token validation, and failed attempts.
extensions Extensions Silent listening (spy), whisper coaching, barge-in calls, and extension dial actions.
queues Queues Agent pause/resume cause codes, queue member logins, and queue call interceptions.
parking Parking Lots Call parking origins, parking retrieval events, and parking timeout drops.
conferences Conferences Room lock/unlock, attendee kicks, mute/unmute commands, and floor control.
active_calls Active Calls Channel hangup overrides, line hold/resume, attended transfers, and blind transfers.
layouts Layouts Grid repositioning, layout creation, widget additions, and global layout publication.
log_profiles Log Profiles Audit trail configuration changes and profile modifications.
roles Roles & Permissions Privilege escalations, RBAC assignment adjustments, and permission level edits.
pause_profiles Pause Profiles Creation, reordering, or alteration of call center agent pause reason codes.
flag_profiles Flag Profiles Visual call tag definitions and color classification rules.
branding Branding White-label logo uploads, favicon replacements, and login welcome text edits.
webrtc WebRTC Settings Modifications to STUN, TURN, or ICE timeout settings.
connection Connection Settings Switchboard node mode toggles (Local vs Remote) and API endpoint updates.

Each module supports five distinct event classifications:

Audit Action Pill Indicator Description & Forensic Purpose
Create (log_create) [ + Create ] (Green) Emits an audit entry when new records, layouts, or profiles are provisioned.
Read (log_read) [ 👁 Read ] (Blue) Logs read operations and sensitive data inspections.
Update (log_update) [ ✎ Update ] (Amber) Logs field-level changes with previous and updated state diffs.
Delete (log_delete) [ ✕ Delete ] (Red) Records record deletions with operator ID, IP address, and timestamp.
Action (log_action) [ ⚡ Action ] (Emerald) Crucial for telephony: logs call transfers, eavesdrops, whisper coaches, and barge-ins.
[ Operator: alexander (1001) ] ──⚡ Action──> [ Eavesdrop on Ext 1045 ] ──> [ ss_switchboard.audit_logs ]

Audit log entries emitted by configured Log Profiles contain comprehensive metadata:

  • Timestamp: High-precision UTC timestamp (YYYY-MM-DD HH:MM:SS.sssZ).
  • User Identity: Account ID, username, and assigned role.
  • Client IP & User-Agent: Originating browser IP address, operating system, and browser engine.
  • Tenant Scope: Invariant numerical tenant_id and domain_id.
  • Target Resource: The affected record ID, extension number, or telephony channel UUID.
  • Payload / Changes: Structured JSON payload detailing modified values and parameters.

[!IMPORTANT] To comply with privacy regulations (such as HIPAA, GDPR, and PCI-DSS), audit logs do not store audio streams. Only the metadata timestamp, supervisory operator ID, and target extension channel UUID are recorded.