Activity log
What is recorded, who can see it, and how long it is kept.
User guide
What is recorded, who can see it, and how long it is kept.
The Staff activity page is your supervision surface: a permanent journal of what your team did — including, deliberately, what they tried to do and were refused.
Who can do this: the Administrator, the built-in Reports Viewer role, and custom global roles granted activity access — activity access cannot be granted to a store-scoped role.

Entries appear within seconds. Each expands into the endpoint called, the device, the IP address and a request id — with "Show everything this action did" pulling together every entry one action produced.
Entry contents are privacy-conscious by design: the journal records that a field changed and rarely its value, and secrets — passwords, tokens, card numbers — are never stored.
Filters narrows by action, record type, entry type (API call / Field change / Sign-in), outcome and store. Each entry's row can also jump to the record it touched, and every staff member's own timeline is available from their page in Staff.
Your plan keeps the journal for a fixed window of recent days, and the page states it plainly: "Only the last 30 days of activity are kept on your plan." The period filter above the table offers "Last 24 hours", "Last 7 days", "Last 14 days" and "Last 30 days" — never a range wider than what is kept. After a downgrade there is a grace period before any narrower window is enforced, so you have time to export what you need.