Skip to main content
Admin Actions / Audit Log — A build-to-order Magento 2 / Adobe Commerce extension that records every backend admin action — l — 1/1Illustrative preview

A build-to-order Magento 2 / Adobe Commerce extension that records every backend admin action

— logins, page visits, entity edits, bulk operations and deletions — with full who/what/when/where context and selective rollback.

What is Admin Actions / Audit Log?

A build-to-order Magento 2 / Adobe Commerce extension that records every backend admin action — logins, page visits, entity edits, bulk operations and deletions — with full who/what/when/where context and selective rollback. Built to order by ECOSIRE for Magento 2 / Adobe Commerce (build-to-order) — indicative price from $999.00 USD; request a quote for a scoped proposal.

Key Features

Logs admin logins, failed login attempts, logout and backend page visits via observers on admin_user_authenticate_after and controller_action_predispatch
Captures field-level before/after diffs on entity create, edit and delete using plugins around repository save()/delete() service contracts
Records full context for every action: admin user, role, IP address, request URL/controller, timestamp, object type, object ID and store view scope
Logs bulk and mass actions per affected record (mass status change, mass delete, attribute mass update) rather than as a single opaque event
Selective rollback — restore a logged entity (or single changed field) to its prior serialized value from the audit grid
Dedicated admin grid under System with column filters, date range, user and action-type filters, and a side-by-side diff viewer
Own admin ACL resource (Ecosire_AdminActionsLog::view / ::rollback) so log access and rollback are restricted independently of other backend rights
CSV and XML export of filtered log entries for SIEM/SOC ingestion or auditor handoff
Cron-driven auto-cleanup with configurable retention window to keep the log table bounded
Read-only REST endpoint to pull audit entries into external compliance and monitoring tooling
Append-friendly schema (declarative schema db_schema.xml) with indexed columns for fast filtering on large logs
Configurable capture scope in Stores → Configuration — choose which entity types, controllers and config paths to track to control log volume

Built to order, done for you

No DIY setup — a working app, built, installed and supported by ECOSIRE.

  1. 1

    You order

    Start with a one-time build price. We scope it with you at kickoff.

  2. 2

    We build & install

    ECOSIRE builds, configures and installs it on your Magento 2.

  3. 3

    Go live + support

    You go live in about one working week, with two weeks of go-live support. Defects in the code we deliver are fixed free of charge.

About this Product

Admin Actions / Audit Log gives security- and compliance-conscious merchants a complete, tamper-evident record of everything that happens inside the Magento 2 backend. Magento Open Source and Adobe Commerce ship only a thin admin action log (admin_user_session plus the report_event table and, on Commerce, the limited Admin Actions Log under System), which records logins and a handful of events but cannot tell you what field changed from what to what, and offers no rollback.

This extension is a proper module under app/code/Ecosire/AdminActionsLog, wired through di.invoke. It uses plugins (interceptors) around save/delete service contracts and observers on core events such as admin_user_authenticate_after, controller_action_predispatch and model_save_after to capture a before/after snapshot of every entity — products, categories, CMS, customers, orders, prices, configuration. Each record stores the user, role, IP address, request URL, timestamp, store view, object type and object ID, plus a serialized field-level diff. Bulk actions (mass status changes, mass deletes via the grid) are logged per affected record, not as one opaque event.

A dedicated grid under System → ECOSIRE Audit Log (its own ACL resource) lets authorized admins filter, inspect a side-by-side diff, and roll back selected changes to the prior value. Retention is handled by a cron job with configurable auto-cleanup, and you can export to CSV/XML for SIEM ingestion or auditor handoff. Read access is exposed over REST for integration.

Because it is build-to-order, ECOSIRE builds, installs and tests it on your Magento install — matched to your version, custom entities and theme — then supports it. There is no instant Marketplace download; you get a clean, code-reviewed module and a real engineer behind it.

What you get

  • Custom Magento 2 module Ecosire/AdminActionsLog installed under app/code (or as a Composer package) on your environment
  • Declarative schema (db_schema.xml) creating the audit and rollback tables with proper indexes and foreign keys
  • Admin grid UI, diff viewer and rollback controller wired through ACL, layout XML and UI components
  • di.xml, events.xml and webapi.xml configuration plus the observers and plugins that capture each action
  • Cron group definition (crontab.xml) for the auto-cleanup/retention job
  • Installation, configuration and rollback runbook, plus a short admin handover walkthrough

Who this is for

Store Owner with Multiple Staff Admins

Runs a merchant with several backend users and contractors and needs to know exactly who changed a price, disabled a product or edited an order — and to undo a mistake fast without a developer or a database restore.

IT Security / Compliance Officer

Must satisfy PCI-DSS, SOC 2 or internal audit requirements for accountability of privileged backend access, and needs immutable who/what/when/where logs with IP and CSV/XML export into the SIEM.

Magento Agency / Solutions Engineer

Manages client stores and wants a clean, code-reviewed audit module installed per environment with version-matched compatibility, ACL-gated rollback and a documented runbook rather than a black-box marketplace plugin.

How Admin Actions / Audit Log Compares

CriterionECOSIRECustom BuildCompetitorMagento 2 Native
Field-level before/after diff of every editIncludedPartial supportPartial supportNot included
Selective rollback of logged changesIncludedPartial supportNot includedNot included
Per-record logging of bulk/mass actionsIncludedPartial supportPartial supportNot included
Captures user, IP, URL, timestamp, store viewIncludedIncludedIncludedPartial support
Built, installed & supported on your install by the vendorIncludedIncludedNot includedNot included
CSV/XML export + REST for SIEM/auditor handoffIncludedPartial supportPartial supportNot included
Dedicated ACL resource to gate rollback separatelyIncludedPartial supportPartial supportNot included
Instant self-service download / one-click installNot includedNot includedIncludedIncluded

Frequently Asked Questions about Admin Actions / Audit Log

How long until the extension is delivered and installed?

This is a build-to-order extension, not an instant download. Typical delivery is 5–10 business days depending on your Magento version (Open Source or Adobe Commerce), any custom entities you want tracked, and environment access. After a short scoping call we build and unit-test the module, then install it on your staging environment for sign-off before production. You receive a firm timeline in writing before work starts.

What ongoing support and updates are included?

Every build includes a warranty period for bug fixes, plus optional ongoing support. Because ECOSIRE delivers the source code, you own the module. We provide compatibility updates for Magento minor/security releases on request and can extend the captured entity scope or retention rules as your store evolves. Support is handled directly by the engineers who built it — there is no third-party marketplace queue.

Does it work on both Magento Open Source and Adobe Commerce?

Yes. The module targets the standard Magento 2 framework (DI, plugins, observers, service contracts, declarative schema) so it runs on both Magento Open Source and Adobe Commerce. On Adobe Commerce it complements — rather than conflicts with — the built-in Admin Actions Log by adding field-level diffs and rollback. We confirm your exact version and edition during scoping and test against it.

Will logging every admin action slow down the backend?

No meaningful impact for normal use. Capture happens on the existing save/delete and dispatch flow with indexed inserts; high-volume work like bulk imports can be excluded from capture via configuration so a 50,000-row product import does not bloat the log. The auto-cleanup cron keeps the table bounded, and the schema is indexed for fast filtering even with millions of rows.

How does rollback work and is it safe?

Each change stores a serialized snapshot of the entity (or the specific changed fields) before and after. Rollback re-applies the prior value through the same repository service contracts, so it respects validation and indexing rather than writing raw SQL. Rollback is gated behind its own ACL resource, so you can grant view-only audit access to most admins and restrict rollback to senior staff. The rollback itself is also logged.

Can we feed the logs into our SIEM or hand them to an auditor?

Yes. You can export any filtered view to CSV or XML directly from the admin grid, and there is a read-only REST endpoint to pull entries programmatically into a SIEM/SOC pipeline or scheduled report. Records include user, role, IP, URL, timestamp, store view and object reference, which is typically what auditors expect for privileged-access accountability.

Request a quote

Admin Actions / Audit Log

A build-to-order Magento 2 / Adobe Commerce extension that records every backend admin action — logins, page visits, entity edits, bulk operations and deletions — with full who/what/when/where context and selective rollback.

  • Logs admin logins, failed login attempts, logout and backend page visits via observers on admin_user_authenticate_after and controller_action_predispatch
  • Captures field-level before/after diffs on entity create, edit and delete using plugins around repository save()/delete() service contracts
  • Records full context for every action: admin user, role, IP address, request URL/controller, timestamp, object type, object ID and store view scope
  • Logs bulk and mass actions per affected record (mass status change, mass delete, attribute mass update) rather than as a single opaque event

Request a Quotation

Tell us about your Admin Actions / Audit Log requirements and we'll send pricing, licensing options and a tailored proposal — usually within one business day.

No payment now. This sends a quote request to our team — we'll follow up by email with pricing and next steps.