Post Author
I want to start with a question I asked myself the first time I read Notion’s help documentation on audit logs. If someone on our team quietly exported every client contract in our workspace last Tuesday, would I ever know? On the Free plan, no. On Plus, no. On Business, the plan that gets you full AI access and private teamspaces for $20 a seat a month, still no. You would need to be on Enterprise, the plan Notion does not price on its website and will not sell you without a sales call, custom pricing via sales that market benchmarks put somewhere around $20 to $35 per seat per month for mid-market organizations.
That is the entire story in miniature. But it is worth walking through slowly, because the story is not really about Notion. It is about a pattern that has quietly become standard practice across enterprise software, one that a small, mostly anonymous group of security engineers has started keeping score on. They built a public list. They call it the Wall of Shame. Notion is on it.
What an Audit Log Actually Does
Strip away the compliance jargon and an audit log is just a record. Who opened this page. Who changed the sharing settings. Who added a new admin. Who exported the whole workspace to their laptop the day before they resigned. Notion’s1 own help documentation walks through the same basic idea: a running account of activity across a workspace, tied to the specific person behind each action, with an IP address attached when one is available. It is not a fancy feature. It is a receipt.
Notion’s list of loggable events is long and, to Notion’s credit, genuinely thorough once you have access to it. The developer documentation by Notion2 breaks events into categories: page events, data source events, workspace events, account events, teamspace events, form events, organization events. Automations created and deleted. Meeting recordings downloaded. Content search queries run by an integration or an external AI tool. If you can do it in Notion, there is very likely an event type for it.

None of that matters if you cannot see it. And on three of Notion’s four pricing tiers, you cannot.
Here is how Notion’s Help Center3 puts it, in a single sentence buried under a note icon: the audit log feature is available to organization owners on the Enterprise Plan. Not Business. Not Plus. Enterprise, full stop.
There is a second detail in that same note that matters more than the headline. Notion’s own documentation confirms that logging only begins once a workspace actually converts to Enterprise. Whatever happened before that switch flips is simply gone, unrecoverable, never captured in the first place. Read that again. It means the exact moment you would most want visibility, the incident that convinced your CFO to finally approve the Enterprise contract, is the one moment guaranteed to be invisible. You can buy the flashlight. You just cannot point it at anything that already happened.
Multiple pricing breakdowns from 2026 confirm the same tier structure from different angles. One reviewer summarizes it flatly: if you need SCIM or audit logs for compliance reasons, Enterprise is the only option. A consulting firm that works with Notion clients writes that Enterprise is where Notion becomes a truly governed, auditable, enterprise-grade platform, which is a polite way of saying that below Enterprise, it isn’t. A compliance-focused vendor comparison lists the audit log among the handful of features that Enterprise adds on top of Business, alongside SCIM provisioning, mandatory MFA, and HIPAA eligibility. Everyone selling advice about Notion pricing has landed on the identical conclusion, because there is only one conclusion to land on. The company drew a hard line and put logging on the far side of it.
The List Notion Didn’t Ask To Be On
A group of security engineers maintains a project called the Audit Logs Wall of Shame4, hosted on a domain that doubles as the joke: audit-logs.tax. The premise is simple. Any vendor that charges a premium for audit log data, or otherwise makes it hard to get, qualifies for inclusion. The maintainers are explicit about their motive. The goal, they write, is to push those building solutions to think of the security engineering customer and to arm defenders with the information they need to protect their own organizations.
Notion sits on that list next to Slack, GitLab, LastPass, Zendesk, Salesforce, and GitHub. The entry for Notion is short. Gating mechanism: Enterprise only. Log issue noted: no API collection. That second line is easy to skim past, but it is its own small indictment. Even the customers who do pay for Enterprise and do get the audit log cannot easily pipe it into the security tooling they already run. Notion5 offers SIEM and DLP connections as a separate Enterprise capability, letting you centralize audit logs in an external system, but that is a further add-on inside the tier that already required a sales call to reach.

The Wall of Shame project cites a specific piece of federal guidance as its north star, and this is where the Notion story stops being a niche complaint about one company’s pricing page and starts looking like a test case for an argument the U.S. government has been making for two years.
In 2023 and 2024, the Cybersecurity and Infrastructure Security Agency ran an unusually direct campaign aimed at software vendors. It was called Secure by Design, and one of its seven core goals was about logging. The language is worth quoting because it is so specific. Companies that sign the pledge commit that, within six months, security audit logs are provided to customers at no additional charge. CISA’s6 own framing goes further, arguing that out of the box, logging and single sign-on should be available at no extra cost, treating them as baseline hygiene rather than premium add-ons.
More than 200 companies eventually signed, including Google, Microsoft, GitHub, Amazon Web Services, Cisco, and Okta, according to CISA’s7 own published list. I looked for Notion on it. I did not find it. That is not proof of anything by itself. The pledge is voluntary, and plenty of reputable companies have simply not gotten around to signing a symbolic federal commitment. But it does mean Notion has made no public promise, to CISA or to anyone else, to move audit logs down the pricing ladder. The company is free to leave the gate exactly where it is, indefinitely, and answer to no one but its own sales targets.
Why did CISA care enough to write a whole pledge goal about logs in the first place? Because of a breach that happened to hit the pledge’s biggest eventual signatory, Microsoft, before the ink on the goal was even dry.
The Microsoft Precedent
According to Bleeping Computer8, in the summer of 2023, a China-linked group tracked as Storm-0558 forged authentication tokens and read email out of Exchange Online accounts belonging to U.S. government officials, eventually pulling roughly 60,000 emails from State Department accounts. The intrusion ran for about a month before anyone noticed. It was caught, according to reporting from multiple outlets, because a federal agency happened to be using a premium logging tier and could see the specific mailbox-access events that revealed the compromise. Hacker News9 reported that the action that flagged the breach, MailItemsAccessed, was a Purview Audit Premium feature. Customers on the standard tier would not have seen it.
The public reaction was fast and unflattering. Senator Ron Wyden went on the record calling the arrangement a way for Microsoft to gouge its customers over basic security features, and he was not alone in that framing. Under sustained pressure from CISA, Microsoft10 backed down within days of the disclosure and announced it would expand free logging capabilities across all Purview Audit standard customers, eventually stretching default retention from 90 days to 180.

CISA Director Jen Easterly welcomed the move, saying she was extremely pleased at the reversal, and later guidance from her agency described the expanded logs as new telemetry that would help organizations hunt business email compromise and insider-risk scenarios they previously could not see at all.
“After working collaboratively for over a year, I am extremely pleased with Microsoft’s decision to make necessary log types available to the broader cybersecurity community at no additional cost”
I keep coming back to one detail in that timeline. Microsoft did not decide gated logging was a security liability on principle. It decided that after a nation-state breach became a front-page story and a sitting U.S. senator started using the word gouge in the press. The economics of the decision only changed once the reputational cost of the old policy exceeded the revenue it protected. Nothing about the underlying software logic changed. The mailbox events existed the whole time. They were simply metered.
That is the mechanism worth sitting with, because it is the same mechanism at work in Notion’s pricing page, just without a Chinese intelligence service to force the issue yet.
Notion did not invent this. It joined a crowded field. Slack requires its top-tier Enterprise Grid plan for audit logs, legal holds, and native data loss prevention, a gate one comparison describes as walling off critical compliance features behind its top tier the same way Atlassian does with Confluence. GitHub offers audit logs more broadly but varies their quality by tier, according to the Wall of Shame maintainers, with standard-tier logs missing IP addresses that enterprise logs include. Salesforce sells its most detailed activity monitoring as a separate paid product called Shield, not even bundled into its highest subscription tier. LastPass, Zendesk, GitLab, Terraform Cloud, Hugging Face, and 1Password all appear on the same list, each with its own flavor of the identical decision: treat the record of what happened in your own software as a feature you sell, not a baseline you owe.
This is, from a pure business standpoint, a rational thing to do. Enterprise buyers have compliance mandates and larger budgets, and audit logging is exactly the kind of feature that a procurement checklist forces someone to pay for regardless of whether they use it every day. Bundling it into the cheapest tier gives away, for free, the one lever that reliably converts a mid-size customer into a six-figure contract. I understand the spreadsheet logic. I have read enough SaaS pricing strategy content to know that a feature which only a fraction of customers actively use, but which compliance teams cannot walk away without, is the single most efficient thing you can put behind a paywall. It converts security anxiety directly into annual recurring revenue.
But the thing being metered is not a nice-to-have. It is the mechanism by which a customer finds out they have been breached.
Who Gets Left Out
Notion’s Enterprise tier is not aimed at a five-person startup. Every pricing breakdown I read pointed the same direction: Enterprise makes sense for companies with more than 250 users, compliance-heavy verticals, and multi-entity organizations. According to Notion Flow11, a consulting firm working directly with Notion customers put a similar floor on it, describing Enterprise as the right fit once a company clears 100 or more employees and starts facing real governance requirements, while noting plenty of 50 to 100 person teams get by fine on Business.
That leaves an enormous middle. A 60-person healthcare startup. A 90-person fintech handling client financial data. A law firm with 40 associates and no dedicated security hire. These are exactly the organizations without the headcount to run a full-time detection and response function, which means the audit log is not a supplement to their security program. For a lot of them, it would be the whole program. And it is precisely these organizations that Notion’s pricing structure prices out, because the sales-led, negotiated, four-figure-minimum nature of Enterprise contracts assumes a level of scale and budget authority that a 60-person company frequently does not have yet.
Notion12 has more than 100 million users and over 4 million paying customers as of this year, according to figures the company itself has publicized, and reported annual revenue north of $600 million. A meaningful share of that base sits in the Free, Plus, and Business tiers, running real client work, HR records, and internal strategy documents through a tool that offers those customers no way to answer the most basic incident-response question there is: what happened, and who did it.

There is a decent counterargument here, and it deserves airtime. Smaller teams genuinely do have simpler threat models. A five-person agency does not need SIEM streaming or session-duration enforcement. Building, maintaining, and supporting a full audit log pipeline costs Notion engineering time and storage, and giving it away at every tier would mean either raising prices across the board or accepting thinner margins on the plans that bring in the least revenue per seat. Reasonable people can disagree about where exactly the line should sit.
What I don’t find convincing is the specific place Notion chose to put it. The company did not simply limit log retention on cheaper plans, the way Slack still gives every customer some baseline visibility. It removed the capability entirely below Enterprise, then declined to backfill anything once a customer does upgrade. Combine those two design choices and you get a policy where the exact customers least equipped to detect a problem on their own are the same customers with zero forensic trail if one occurs, and where paying your way into visibility after the fact buys you nothing about the past. That is a design decision, not an inevitability. GitHub’s approach, flawed as the Wall of Shame maintainers find it, still gives every customer some baseline logging. Notion’s does not.
What This Actually Costs, In Practice
Picture the ordinary way this plays out, because it rarely involves a nation-state. It involves a departing employee. Someone gives notice, works their final two weeks, and quietly duplicates a handful of sensitive databases into a personal workspace before their access is revoked. Or it involves a compromised account, a phishing email that catches someone tired on a Friday afternoon, followed by three days of unnoticed access before the password gets reset for unrelated reasons. On Business or below, the workspace owner has no log to consult after the fact. No timestamp, no IP address, no list of what was viewed or exported. The absence is not a gap in the evidence. It is the entire evidentiary record, or rather the entire lack of one.
Compliance frameworks are not shy about this. SOC 2 audits, the standard so common that a cottage industry of Notion-based SOC 2 templates has sprung up to help companies pass them, treat activity monitoring as core evidence of operating controls. A company selling a free SOC 2 compliance system built on top of Notion has to acknowledge, if only implicitly, the strange loop this creates: you can run your compliance operating system inside Notion while Notion itself withholds the one control an auditor most wants to see, unless you pay for the tier that provides it.
I think it is acting the way almost every SaaS company its size acts, which is exactly the problem. The Wall of Shame exists because this behavior is common enough to need a public list. The CISA pledge exists because a federal agency decided common practice and secure practice had drifted far enough apart to warrant a formal campaign, complete with a specific number attached, no additional charge, six months. Microsoft only moved because a breach made the gap between those two things impossible to ignore.
Notion has not had its Storm-0558 moment yet, as far as anyone has reported. Maybe it never will. Maybe the sales-led Enterprise model quietly does its job, converting exactly the customers who need audit logging most into paying customers before anything goes wrong, and the whole arrangement works out fine in practice even if it looks uncomfortable on paper. Or maybe somewhere on a Business plan right now, a company with client contracts, cap tables, or patient intake forms living in a Notion workspace is one departing employee away from finding out, the hard way, exactly what the fine print meant when it said Enterprise only.
Sources
- “Workspace audit log in Notion | Notion Help – Notion Help Center” Notion Help Notion Help Center, www.notion.com/help/audit-log. Accessed 26 July 2026. ↩︎
- “Audit log events” Notion Docs, developers.notion.com/compliance/audit-log-events. Accessed 26 July 2026. ↩︎
- “Workspace audit log in Notion | Notion Help – Notion Help Center” Notion Help Notion Help Center, www.notion.com/help/audit-log. Accessed 26 July 2026. ↩︎
- “The Audit Log Wall of Shame” Audit Logs Wall of Shame, audit-logs.tax/. Accessed 27 July 2026. ↩︎
- “Notion Enterprise security provisions” www.notion.com/help/guides/notion-enterprise-security-provisions. Accessed 27 July 2026. ↩︎
- “Secure by Design” CISA, www.cisa.gov/securebydesign. Accessed 27 July 2026. ↩︎
- “CISA Announces Secure by Design Commitments from Leading Technology Providers” CISA, 8 May 2024, www.cisa.gov/news-events/news/cisa-announces-secure-design-commitments-leading-technology-providers. Accessed 27 July 2026. ↩︎
- Bleeping Computer, www.bleepingcomputer.com/news/security/microsoft-expands-free-logging-capabilities-after-may-breach/. Accessed 27 July 2026. ↩︎
- News, The Hacker. “Microsoft Expands Free Logging Capabilities for all U.S. Federal Agencies” 27 July 2026, thehackernews.com/2024/02/microsoft-expands-free-logging.html. Accessed 27 July 2026. ↩︎
- Jakkal, Vasu. “How Microsoft is expanding cloud logging to give customers deeper security visibility” Microsoft Security Blog, 19 July 2023, www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/. Accessed 27 July 2026. ↩︎
- “Notion Pricing in 2026 for growing Teams: Business vs Enterprise Plan Breakdown” Notion Pricing in 2026 for growing Teams: Business, notionflows.com/blog-post/notion-pricing-in-2026-for-growing-teams-business-vs-enterprise-plan-breakdown. Accessed 27 July 2026. ↩︎
- Zhao, Ivan. “100 million people now use Notion” 3 Sept. 2024, www.notion.com/blog/100-million-of-you. Accessed 27 July 2026. ↩︎
