Plan requirement
| Subscription | Any plan |
| Access | Admin |
Sometimes, in the audit log. The answer is usually that nobody did: anybody who emails you gets a record without an admin being involved.
Where to look
The audit log records administrative actions, including user creation where a person or an integration performed it. Filter by date and by the user in question.
Most users create themselves
Anybody who emails an address Zendesk watches gets a record automatically. No admin was involved, and there is nobody to attribute it to.
That accounts for the overwhelming majority of records in any account.
The question underneath
"Why do we have so many users?" Because every customer who ever wrote in has one. It costs nothing and it is not a problem.
"Where did this odd record come from?" Usually an import, an integration, or a spam message. The audit log or the user's first ticket tells you which.
"Who gave this person access?" A different question, and one the audit log genuinely answers: role changes are recorded.
Access changes are the ones that matter
Who made somebody an agent, or an admin, and when. That is recorded, and it is what an access review or an incident investigation actually needs.
Retention is limited
The audit log does not go back indefinitely. For anything you may need to evidence later, export it rather than assuming it will be there.
Comments
0 comments
Article is closed for comments.