Changed log retention
— Workspace settings90 days365 days
Rhea Patel rhea@acme.com · · IP 203.0.113.42
A compliance-grade trail with named actors, before and after values, IP addresses, and a stated retention window — plus a count of what the active filter is hiding.
components/settings-audit-log.tsxnpx hoverlab add settings-audit-log
Or over MCP, from your editor's agent — no account needed.
Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.
Start a page with this section — add more, order them, and leave with the page source.
5 entries
90 days365 days
Rhea Patel rhea@acme.com · · IP 203.0.113.42
Sam Okafor sam@acme.com · · IP 198.51.100.9
Rhea Patel rhea@acme.com · · IP 203.0.113.42
Team, 24 seatsStudio, 40 seats
Billing system system · · IP —
Jordan Lee jordan@acme.com · · IP 192.0.2.77
Entries are kept for 365 days on your plan and then deleted. Export before that if you need them for longer — nothing here can be recovered afterwards.
Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.
'use client'
/**
* <SettingsAuditLog> — who changed what, filterable, and honest about
* retention.
*
* The catalog already has an activity timeline and an activity feed. Both
* are product surfaces: they tell a user what happened in their workspace.
* An audit log is a compliance surface, and the difference is not cosmetic —
* it is answering a question asked by somebody who does not trust the
* answer, usually months later, usually during a security review.
*
* WHAT MAKES THIS AN AUDIT LOG RATHER THAN A FEED
*
* - The actor is always named, and never as "you". A feed says "You
* removed a member"; an audit log says which account did it, from which
* IP, because the reader is not the actor.
* - Entries have before/after values, not verbs. "Changed the retention
* period" is useless in a review; "30 days → 365 days" is the answer.
* - It states its own retention window. A log that silently drops entries
* older than 90 days while presenting itself as complete is worse than
* no log, and this is the fact vendors most often omit.
*
* THE FILTER IS PART OF THE EVIDENCE
*
* When a filter is active the header says how many entries are hidden by
* it. A reader who exports a filtered log and files it as "the log" is the
* failure mode; naming the filtered-out count in the same line as the
* export button is the cheapest guard against it.
*
* ACCESSIBILITY: the filter is a labelled `<select>` rather than a custom
* menu, results announce through `aria-live`, and each entry is an
* `<article>` with its timestamp in a `<time datetime>` so the machine
* reading matches the human one.
*/
import * as React from 'react'
import { ArrowRight, Download, Info, Shield } from 'lucide-react'
export interface AuditEntry {
id: string
actor: string
actorEmail: string
action: string
target: string
/** ISO 8601. Rendered through `<time>` so it is machine-readable. */
at: string
ip: string
before?: string
after?: string
category: 'access' | 'billing' | 'security' | 'data'
}
export interface SettingsAuditLogProps {
entries?: AuditEntry[]
/** Days of history the plan retains. Named on screen — see the header. */
retentionDays?: number
className?: string
}
const DEFAULT_ENTRIES: AuditEntry[] = [
{
id: '1',
actor: 'Rhea Patel',
actorEmail: 'rhea@acme.com',
action: 'Changed log retention',
target: 'Workspace settings',
at: '2026-08-30T14:22:00Z',
ip: '203.0.113.42',
before: '90 days',
after: '365 days',
category: 'security',
},
{
id: '2',
actor: 'Sam Okafor',
actorEmail: 'sam@acme.com',
action: 'Removed member',
target: 'jordan@acme.com',
at: '2026-08-30T09:05:00Z',
ip: '198.51.100.9',
category: 'access',
},
{
id: '3',
actor: 'Rhea Patel',
actorEmail: 'rhea@acme.com',
action: 'Rotated API key',
target: 'prod-ingest-key',
at: '2026-08-29T18:40:00Z',
ip: '203.0.113.42',
category: 'security',
},
{
id: '4',
actor: 'Billing system',
actorEmail: 'system',
action: 'Changed plan',
target: 'Acme Corp',
at: '2026-08-28T02:00:00Z',
ip: '—',
before: 'Team, 24 seats',
after: 'Studio, 40 seats',
category: 'billing',
},
{
id: '5',
actor: 'Jordan Lee',
actorEmail: 'jordan@acme.com',
action: 'Exported dataset',
target: 'customers.csv (18,402 rows)',
at: '2026-08-27T11:13:00Z',
ip: '192.0.2.77',
category: 'data',
},
]
const CATEGORY_LABEL: Record<AuditEntry['category'], string> = {
access: 'Access',
billing: 'Billing',
security: 'Security',
data: 'Data',
}
const CATEGORY_STYLE: Record<AuditEntry['category'], string> = {
access: 'bg-muted text-muted-foreground',
billing: 'bg-primary/10 text-primary',
security: 'bg-destructive/10 text-destructive',
data: 'bg-amber-500/10 text-amber-600 dark:text-amber-400',
}
function formatWhen(iso: string): string {
return new Date(iso).toLocaleString('en-US', {
month: 'short',
day: 'numeric',
hour: 'numeric',
minute: '2-digit',
timeZone: 'UTC',
timeZoneName: 'short',
})
}
export function SettingsAuditLog({
entries = DEFAULT_ENTRIES,
retentionDays = 365,
className = '',
}: SettingsAuditLogProps) {
/*
Per-instance prefix for every id this block emits.
The literals these replaced were a latent duplicate the moment the
block appeared twice on one document, and `aria-labelledby` on a
duplicated id resolves to the first match -- so the second copy was
labelled by the first copy's heading. Client component, so `useId` is
the right tool.
*/
const uid = React.useId()
const [category, setCategory] = React.useState<'all' | AuditEntry['category']>('all')
const shown = category === 'all' ? entries : entries.filter((e) => e.category === category)
const hidden = entries.length - shown.length
return (
<section
className={`rounded-2xl border border-border bg-card text-card-foreground ${className}`}
>
<header className="border-b border-border p-5 sm:p-6">
<div className="flex flex-wrap items-start justify-between gap-3">
<div>
<h2 className="flex items-center gap-2 text-base font-semibold">
<Shield aria-hidden className="h-4 w-4 text-muted-foreground" />
Audit log
</h2>
<p aria-live="polite" className="mt-1 text-sm text-muted-foreground">
{shown.length} {shown.length === 1 ? 'entry' : 'entries'}
{/*
Named next to the export button on purpose. An export of a
filtered log filed as "the log" is the failure this sentence
exists to prevent.
*/}
{hidden > 0 ? (
<span className="font-medium text-foreground"> · {hidden} hidden by the filter</span>
) : null}
</p>
</div>
<div className="flex items-center gap-2">
<label className="sr-only" htmlFor={`${uid}-audit-category`}>
Filter by category
</label>
<select
id={`${uid}-audit-category`}
value={category}
onChange={(event) =>
setCategory(event.target.value as 'all' | AuditEntry['category'])
}
className="rounded-lg border border-border bg-background px-3 py-1.5 text-sm focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring"
>
<option value="all">All categories</option>
{Object.entries(CATEGORY_LABEL).map(([value, label]) => (
<option key={value} value={value}>
{label}
</option>
))}
</select>
<button
type="button"
className="inline-flex items-center gap-1.5 rounded-lg border border-border px-3 py-1.5 text-sm font-medium transition-colors hover:bg-muted focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring"
>
<Download aria-hidden className="h-3.5 w-3.5" />
Export
</button>
</div>
</div>
</header>
<ul className="divide-y divide-border">
{shown.map((entry) => (
<li key={entry.id}>
<article className="p-5 sm:p-6">
<div className="flex flex-wrap items-center gap-2">
<span
className={`rounded px-1.5 py-0.5 text-[11px] font-semibold uppercase tracking-wide ${CATEGORY_STYLE[entry.category]}`}
>
{CATEGORY_LABEL[entry.category]}
</span>
{entry.action ? (
<h3 data-stress-ignore className="text-sm font-semibold">{entry.action}</h3>
) : null}
<span className="text-sm text-muted-foreground">— {entry.target}</span>
</div>
{/* Before → after, where there is one. The reason a review asks. */}
{entry.before && entry.after ? (
<p className="mt-2.5 flex flex-wrap items-center gap-2 text-sm">
<span className="rounded bg-muted px-2 py-0.5 font-mono text-xs text-muted-foreground line-through">
{entry.before}
</span>
<ArrowRight aria-hidden className="h-3.5 w-3.5 text-muted-foreground rtl:rotate-180" />
<span className="rounded bg-primary/10 px-2 py-0.5 font-mono text-xs text-primary">
{entry.after}
</span>
</p>
) : null}
<p className="mt-2.5 text-xs text-muted-foreground">
<span className="font-medium text-foreground">{entry.actor}</span>{' '}
<span className="font-mono">{entry.actorEmail}</span>
{' · '}
<time dateTime={entry.at}>{formatWhen(entry.at)}</time>
{' · '}
IP <span className="font-mono">{entry.ip}</span>
</p>
</article>
</li>
))}
</ul>
<p className="flex items-start gap-2 border-t border-border p-5 text-xs text-muted-foreground sm:px-6">
<Info aria-hidden className="mt-0.5 h-3.5 w-3.5 shrink-0" />
Entries are kept for {retentionDays} days on your plan and then deleted. Export
before that if you need them for longer — nothing here can be recovered
afterwards.
</p>
</section>
)
}
bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.Drop it at components/settings-audit-log.tsx and import it where you need the section:
import { SettingsAuditLog } from '@/components/settings-audit-log'1 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.
Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.
| Prop | Type | Default |
|---|---|---|
entries | AuditEntry[] | DEFAULT_ENTRIES |
retentionDaysDays of history the plan retains. Named on screen — see the header. | number | 365 |
className | string | '' |
The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.
This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.
<!--
Audit Log — markup from the Hoverlab catalog.
This is the block rendered once to HTML and wrapped as a component
file. It is not a port of the React source: the Tailwind classes carry
the design, which is the part that took the work, and they are the same
in every framework.
This block is interactive in React and the handlers are NOT here.
Buttons, toggles and menus render in their initial state and do
nothing until you wire them up.
-->
<section class="rounded-2xl border border-border bg-card text-card-foreground ">
<header class="border-b border-border p-5 sm:p-6">
<div class="flex flex-wrap items-start justify-between gap-3">
<div>
<h2 class="flex items-center gap-2 text-base font-semibold"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-shield h-4 w-4 text-muted-foreground" aria-hidden="true"><path d="M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"></path></svg>Audit log</h2>
<p aria-live="polite" class="mt-1 text-sm text-muted-foreground">5 entries</p>
</div>
<div class="flex items-center gap-2">
<label class="sr-only" for="_R_0_-audit-category">Filter by category</label>
<select id="_R_0_-audit-category" class="rounded-lg border border-border bg-background px-3 py-1.5 text-sm focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring">
<option value="all" selected="">All categories</option>
<option value="access">Access</option>
<option value="billing">Billing</option>
<option value="security">Security</option>
<option value="data">Data</option>
</select>
<button type="button" class="inline-flex items-center gap-1.5 rounded-lg border border-border px-3 py-1.5 text-sm font-medium transition-colors hover:bg-muted focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-download h-3.5 w-3.5" aria-hidden="true"><path d="M12 15V3"></path><path d="M21 15v4a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-4"></path><path d="m7 10 5 5 5-5"></path></svg>Export</button>
</div>
</div>
</header>
<ul class="divide-y divide-border">
<li>
<article class="p-5 sm:p-6">
<div class="flex flex-wrap items-center gap-2">
<span class="rounded px-1.5 py-0.5 text-[11px] font-semibold uppercase tracking-wide bg-destructive/10 text-destructive">Security</span>
<h3 data-stress-ignore="true" class="text-sm font-semibold">Changed log retention</h3>
<span class="text-sm text-muted-foreground">— Workspace settings</span>
</div>
<p class="mt-2.5 flex flex-wrap items-center gap-2 text-sm">
<span class="rounded bg-muted px-2 py-0.5 font-mono text-xs text-muted-foreground line-through">90 days</span>
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-arrow-right h-3.5 w-3.5 text-muted-foreground rtl:rotate-180" aria-hidden="true">
<path d="M5 12h14"></path>
<path d="m12 5 7 7-7 7"></path>
</svg>
<span class="rounded bg-primary/10 px-2 py-0.5 font-mono text-xs text-primary">365 days</span>
</p>
<p class="mt-2.5 text-xs text-muted-foreground"><span class="font-medium text-foreground">Rhea Patel</span> <span class="font-mono">rhea@acme.com</span> · <time dateTime="2026-08-30T14:22:00Z">Aug 30, 2:22 PM UTC</time> · IP <span class="font-mono">203.0.113.42</span></p>
</article>
</li>
<li>
<article class="p-5 sm:p-6">
<div class="flex flex-wrap items-center gap-2">
<span class="rounded px-1.5 py-0.5 text-[11px] font-semibold uppercase tracking-wide bg-muted text-muted-foreground">Access</span>
<h3 data-stress-ignore="true" class="text-sm font-semibold">Removed member</h3>
<span class="text-sm text-muted-foreground">— jordan@acme.com</span>
</div>
<p class="mt-2.5 text-xs text-muted-foreground"><span class="font-medium text-foreground">Sam Okafor</span> <span class="font-mono">sam@acme.com</span> · <time dateTime="2026-08-30T09:05:00Z">Aug 30, 9:05 AM UTC</time> · IP <span class="font-mono">198.51.100.9</span></p>
</article>
</li>
<li>
<article class="p-5 sm:p-6">
<div class="flex flex-wrap items-center gap-2">
<span class="rounded px-1.5 py-0.5 text-[11px] font-semibold uppercase tracking-wide bg-destructive/10 text-destructive">Security</span>
<h3 data-stress-ignore="true" class="text-sm font-semibold">Rotated API key</h3>
<span class="text-sm text-muted-foreground">— prod-ingest-key</span>
</div>
<p class="mt-2.5 text-xs text-muted-foreground"><span class="font-medium text-foreground">Rhea Patel</span> <span class="font-mono">rhea@acme.com</span> · <time dateTime="2026-08-29T18:40:00Z">Aug 29, 6:40 PM UTC</time> · IP <span class="font-mono">203.0.113.42</span></p>
</article>
</li>
<li>
<article class="p-5 sm:p-6">
<div class="flex flex-wrap items-center gap-2">
<span class="rounded px-1.5 py-0.5 text-[11px] font-semibold uppercase tracking-wide bg-primary/10 text-primary">Billing</span>
<h3 data-stress-ignore="true" class="text-sm font-semibold">Changed plan</h3>
<span class="text-sm text-muted-foreground">— Acme Corp</span>
</div>
<p class="mt-2.5 flex flex-wrap items-center gap-2 text-sm">
<span class="rounded bg-muted px-2 py-0.5 font-mono text-xs text-muted-foreground line-through">Team, 24 seats</span>
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-arrow-right h-3.5 w-3.5 text-muted-foreground rtl:rotate-180" aria-hidden="true">
<path d="M5 12h14"></path>
<path d="m12 5 7 7-7 7"></path>
</svg>
<span class="rounded bg-primary/10 px-2 py-0.5 font-mono text-xs text-primary">Studio, 40 seats</span>
</p>
<p class="mt-2.5 text-xs text-muted-foreground"><span class="font-medium text-foreground">Billing system</span> <span class="font-mono">system</span> · <time dateTime="2026-08-28T02:00:00Z">Aug 28, 2:00 AM UTC</time> · IP <span class="font-mono">—</span></p>
</article>
</li>
<li>
<article class="p-5 sm:p-6">
<div class="flex flex-wrap items-center gap-2">
<span class="rounded px-1.5 py-0.5 text-[11px] font-semibold uppercase tracking-wide bg-amber-500/10 text-amber-600 dark:text-amber-400">Data</span>
<h3 data-stress-ignore="true" class="text-sm font-semibold">Exported dataset</h3>
<span class="text-sm text-muted-foreground">— customers.csv (18,402 rows)</span>
</div>
<p class="mt-2.5 text-xs text-muted-foreground"><span class="font-medium text-foreground">Jordan Lee</span> <span class="font-mono">jordan@acme.com</span> · <time dateTime="2026-08-27T11:13:00Z">Aug 27, 11:13 AM UTC</time> · IP <span class="font-mono">192.0.2.77</span></p>
</article>
</li>
</ul>
<p class="flex items-start gap-2 border-t border-border p-5 text-xs text-muted-foreground sm:px-6"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-info mt-0.5 h-3.5 w-3.5 shrink-0" aria-hidden="true"><circle cx="12" cy="12" r="10"></circle><path d="M12 16v-4"></path><path d="M12 8h.01"></path></svg>Entries are kept for 365 days on your plan and then deleted. Export before that if you need them for longer — nothing here can be recovered afterwards.</p>
</section>
What each framework gets across the whole catalog — effects convert properly; this rung is markup.
The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.
Want the whole screen instead of this one section? Open a page and copy it entire.
All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.
Browse SettingsCopying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.
Sidebar-and-panel settings shell that becomes a horizontal scroller on mobile instead of collapsing into a select.
Avatar, fields and a character counter, with a sticky save bar that only appears once something has genuinely changed.
Member list with role selects, pending invites shown inline, and the last owner locked so a workspace cannot be orphaned.
Masked keys, a create flow that reveals the secret exactly once, and a revoke that confirms before it fires.
Destructive actions gated by typing the resource name exactly — the pattern GitHub and Stripe use, and for good reason.
The screen people go looking for after losing a laptop. Sign out everywhere states what it does not reach — API keys keep working — locations are written as estimates, and this device is labelled rather than revocable by misclick.
Every event against every delivery channel in one grid, with column toggles and required rows that show the policy instead of a disabled checkbox.