---
title: How to configure the Audit Trail permission set
description: Learn how to configure IAM permissions for accessing Scaleway's Audit Trail, enabling event tracking across Organizations and Projects.
tags: audit-trail events tracking iam permissions
dates:
  validation: 2025-06-03
  posted: 2024-11-28
---

This page teaches you how to configure the necessary IAM permission set to access [Audit Trail](/audit-trail/concepts/#audit-trail).

## Configure the Audit Trail permission set

To start using Audit Trail you need to configure the `AuditTrailReadOnly` or the `OrganizationManager` permission sets in [IAM](/iam/concepts/#iam).
The `OrganizationManager` permission set is included in the `Administrators` group which is created by default whenever a new Organization is created.
The [scope](/iam/concepts/#scope) of these permission sets is at [Organization](/iam/concepts/#organization) level.

1. Click **IAM & API keys** on the top-right drop-down menu of the Scaleway console. The **Users** tab of the [Identity and Access Management dashboard](https://console.scaleway.com/iam/users) displays.
2. Refer to the page on how to [create an IAM policy](/iam/how-to/create-policy/) and follow steps one to five.
3. Select the **Access to Organization features** scope and click **Validate** to move on to the next step.
    <Message type="important">
     The **Access to Organization features** scope allows you to give the [principal](/iam/concepts/#principal) permissions to Organization-level features such as IAM, Audit Trail, billing, support and abuse tickets, and project management.
    </Message>
4. Click the **Monitoring** category in the **Products** section, then choose the **AuditTrailReadOnly** permission set.
5. Click **Validate**.
6. Click **Create policy**.

## Configure Audit Trail access via the IAM Administrators group

You can also use Audit Trail if you are part of the IAM `Administrators` [group](/iam/concepts/#group).

1. Follow the [following procedure](/iam/how-to/manage-members/) until step 3.
2. Click the drop-down under **Add to an existing group** and add the users to the **Administrators** group.
3. Click **Invite** to send the invitation. The user receives an email inviting them to accept your invitation. If they do not already have a Scaleway account, they will be prompted to [create one](/account/how-to/create-an-account/) first.
4. The user will appear in the **Users** tab** once they have accepted the invitation.
