The following list of audit events are supported for Slack for Enterprise:
| Event Name | Description |
|---|---|
| admin_removed | An admin was removed. |
| billing_address_added | A billing address was added. Includes a details parameter noting the timestamp the TOS was accepted. |
| custom_tos_accepted | A team member accepted a custom terms of service agreement. |
| emoji_added | An emoji was added. Includes a details parameter with the name of the emoji. |
| emoji_aliased | An emoji was given an alias. Includes a details parameter with the name of the alias. |
| emoji_removed | An emoji was removed. Includes a details parameter with the name of the emoji. |
| emoji_renamed | An emoji was renamed. Includes a details parameter with the previous and new names of the emoji. |
| file_downloaded | A file was downloaded. |
| file_public_link_created | A public link was created for a file. |
| file_public_link_revoked | A public link was revoked from a file. |
| file_uploaded | A file was uploaded. |
| guest_created | A guest was created. |
| guest_deactivated | A guest was deactivated. |
| guest_reactivated | A guest was reactivated after having been deactivated. |
| migration_scheduled | A migration was scheduled. |
| organization_created | An enterprise grid organization was created. |
| organization_deleted | An enterprise grid organization was deleted. |
| owner_removed | An owner was removed. |
| owner_transferred | An owner was transferred. |
| role_change_to_admin | A team member was made an admin. |
| role_change_to_guest | A team member was made a guest. |
| role_change_to_owner | A team member was made an owner. |
| role_change_to_user | A team member was a user. |
| user_created | A team member was created. |
| user_deactivated | A team member was deactivated. |
| user_login | A team member logged in. |
| user_logout | A team member logged out. |
| user_reactivated | A team member was reactivated after having been deactivated. |
| workspace_accepted_migration | An administrator on a workspace has accepted an invitation to migrate to a grid org. |
| workspace_declined_migration | An administrator on a workspace has declined an invitation to migrate to a grid org. |
| workspace_deleted | A workspace in an organization was deleted. |
| workspace created | A workspace in an organization has been created. |

