# Activity Log Viewer

Look up who did what in Kiteworks over a date range, with IP address and result, read-only.

Calls get_admin_activity for a start and end date-time up to 30 days apart. Each row gives the event name, description, user, user ID, IP address, client (such as Kiteworks MCP), success flag and time, and you can filter by user or by one folder's own events; free-text search is not supported. IP addresses are personal data, so handle them under your privacy policy; this is a convenience view, not a forensic record. Read-only. Works only for Kiteworks admins on a tenant whose admin has scoped the Kiteworks MCP app; other users get a permission error.

**Category:** Governance & Retention
**Tags:** native-mcp, audit, activity-log

## Example prompts

**Prompt:** "Show what Ana Ruiz did in Kiteworks between 1 and 7 October 2026."

> Reading the activity log for Ana Ruiz, 1–7 October 2026…
> The window is at most 30 days. IP addresses are personal data: handle them under your privacy policy. This is not a forensic record.
> Built into Kiteworks MCP — no separate plugin install needed. Needs a Kiteworks admin; other users get a permission error.

## Kiteworks MCP tools

- `get_admin_activity`

Install: see https://agents.kiteworks.com/catalog/mcp-activity-log for current setup steps.

Canonical URL: https://agents.kiteworks.com/catalog/mcp-activity-log
