DesignOps guide
The Figma activity audit: how to export and read Figma Admin activity logs
A practical guide for DesignOps leaders. Get the data out of Figma, understand every field that matters, and turn it into evidence about focus, momentum, friction and seat use.
- Updated:
- 26 September 2026
- By:
- MoreThought, makers of FlowStatus
- Reading time:
- 11 minutes
Summary
Why audit Figma activity
For most design organisations, Figma is where the work actually happens, and its activity log is the most complete record of how that work flows. A structured audit answers questions that otherwise rely on anecdote:
- Where is attention fragmented across too many files or projects?
- Which projects are moving steadily, and which have stalled or gone dormant?
- Who is building, and who is only watching?
- Which paid seats have had no productive activity for months?
Our 43-project benchmark found that file-switching measured from these logs was the strongest predictor of project outcomes among the factors examined, and that the signal is visible in the first three weeks. The audit below lets you compute the same measures yourself.
Before you start
| Requirement | CSV export from Admin | Activity Logs API |
|---|---|---|
| Figma plan | Organization or Enterprise | Enterprise |
| Role | Organisation admin | Organisation admin authorises the app |
| Access method | Admin settings → Activity → export | OAuth app with org:activity_log_read |
| Best for | One-off audits, quarterly reviews | Continuous monitoring, large organisations |
| Effort | Minutes per export | One-off setup, then automatic |
You will also want your members list (exported from Admin) if you plan to audit seat use, and a simple mapping of Figma teams to your org structure.
Method 1: export a CSV from Figma Admin
- 1
Sign in as an organisation admin
Activity logs are only visible to Figma organisation admins.
- 2
Open Admin settings
From your organisation in Figma's file browser, open Admin (Admin settings).
- 3
Open the Activity tab
Select the Activity (activity log) tab to see organisation events.
- 4
Set the date range and filters
Choose a window (90 days is a good first audit) and, optionally, filter by event type or user.
- 5
Export to CSV
Export the filtered log to CSV. Large ranges may need to be exported in monthly chunks.
- 6
Store the file securely
The export contains personal data such as email addresses. Keep it in an access-controlled location and delete raw copies once processed.
Method 2: use the Activity Logs API
On Enterprise, the same events are available programmatically. Create an OAuth app owned by your organisation, request the read-only org:activity_log_read scope, and have an organisation admin authorise it.
| Parameter | Meaning |
|---|---|
start_time | Start of the window, as a Unix timestamp in seconds |
end_time | End of the window, as a Unix timestamp in seconds |
events | Optional comma-separated list of event types to include |
limit | Events per page, up to 1,000 |
cursor | Pagination cursor returned in the previous response |
import time, requests
TOKEN = "..." # OAuth access token with org:activity_log_read
URL = "https://api.figma.com/v1/activity_logs"
def fetch_activity(start_ts: int, end_ts: int):
params = {"start_time": start_ts, "end_time": end_ts, "limit": 1000}
while True:
r = requests.get(URL, params=params,
headers={"Authorization": f"Bearer {TOKEN}"})
if r.status_code == 429: # rate limited: back off and retry
time.sleep(30); continue
r.raise_for_status()
meta = r.json().get("meta", {})
yield from meta.get("activity_logs", [])
if not meta.get("next_page") or not meta.get("cursor"):
break
params["cursor"] = meta["cursor"]
time.sleep(1)Anatomy of an activity log record
The CSV export and the API describe the same event in slightly different shapes.
| CSV column | API field | Use it for |
|---|---|---|
| Timestamp | timestamp | Sequencing, sessions, active days, gaps |
| Actor Email | actor.email | Attributing activity to people (then aggregate to teams) |
| Event Name | action.type | Separating views from creates, renames, moves and exports |
| Acted On Name (User) | entity.name | Human-readable file name (can change on rename) |
| Acted On ID or Key | entity.key | Stable file identifier: always key analysis on this |
| — | entity.editor_type | Distinguishing Figma design, FigJam, Slides and other file types |
| — | context (project, team) | Attributing files to projects and teams |
The events that matter for DesignOps
Activity-log exports use event names such as fig_file_view. For flow analysis, file events matter most. Administrative events (membership, permissions, seat changes) matter for licence and security reviews.
| Event | What happened | What it tells you |
|---|---|---|
fig_file_create | A new file was created | Building activity; strongest sign of a working seat |
fig_file_view | A file was opened or viewed | Attention: the backbone of switch rate and sessions |
fig_file_view_prototype | A prototype was viewed | Review and testing activity; stakeholder engagement |
fig_file_rename | A file was renamed | Active ownership and housekeeping |
fig_file_move | A file moved between projects or teams | Reorganisation; can distort project attribution |
fig_file_duplicate | A file was duplicated | Branching or forking work; templates in use |
fig_file_export | Assets or a file were exported | Handoff or delivery moments |
The seven-step Figma activity audit
- 1
Define the question and window
Start with one or two leadership questions, such as “Where are we most fragmented?” or “Which seats are idle before renewal?”. Use a 90-day window: long enough to see patterns, short enough to act on.
- 2
Clean the data
Remove service accounts and integrations, drop exact duplicates, convert timestamps to UTC and always key files by
Acted On ID or Key, because names change. - 3
Map files to work
Attribute each file to a project and team (from API context or your naming conventions), then to divisions. Every finding should be readable at project and team level.
- 4
Separate builders from watchers
Anyone with create, rename, move, duplicate or export actions is a builder; view-only people are watchers. The benchmark found viewer-heavy teams scored lower on outcomes. Visibility is not contribution.
- 5
Look for fragmented attention
Follow each designer's sequence of file events. Are they sustaining attention on a few files, or hopping between many? In the benchmark, file-switching was the strongest predictor of project outcomes. See the methodology for why it matters.
- 6
Look for stalls and rework
Plot activity per project over time. Steady activity signals momentum. Long quiet spells, projects that never regain pace, and repeated bursts of rework that never settle are the visible forms of friction.
- 7
Check seats and report
Join to the members list and list paid seats with no productive actions in the window. Report findings by team and project, with a short list of interventions, not a league table of people.
Interpreting what you find
| What you see | What it may mean | What to do |
|---|---|---|
| Constant file-hopping across a team | Too many parallel projects; attention residue | Cut concurrent work in progress before adding people |
| Many watchers, few builders on a project | Review-heavy, unclear ownership | Name owners; move reviews to scheduled crits |
| Work happening on only a few days | Blocked, deprioritised or understaffed | Find the pending decision; pause or close explicitly |
| Long dormant spells | Paused work that may restart cold | Re-brief before restarting; archive if dead |
| Repeated rounds of rework that keep growing | Scope churn, conflicting feedback | Reset scope and decision-makers |
| Paid seats with no productive actions in 90 days | Over-licensing, role changes | Review with the person, then reassign or downgrade |
Look at new projects' first three weeks first. In the benchmark, early switching, activity and momentum correlated 0.97–0.98 with the final picture, which makes them the most useful early warning you have.
Common pitfalls
- Keying on file names. Renames split one file into several. Always use the file key.
- Library and template files. Design system libraries attract views from everyone and inflate switching. Analyse them separately.
- Bulk moves during reorganisations. A burst of
fig_file_moveevents is housekeeping, not work. - Time zones. Mixed local times break session and active-day calculations. Convert to UTC first.
- Service accounts and guests. Integrations and external collaborators can dominate counts. Tag and exclude them.
- Viewer-heavy organisations. Large numbers of view-only users lower apparent switching for reasons unrelated to focus.
- Single snapshots. One export tells you where you are; a series tells you whether changes are working.
Privacy and governance
Activity logs identify people, so UK and EU GDPR apply. A defensible audit usually has:
- A documented purpose (operational health, capacity, licence management) and lawful basis, typically legitimate interest supported by an assessment.
- Restricted access to raw exports, with raw files deleted once aggregated.
- Reporting at team, project and division level, not individual rankings.
- Clear communication to staff, and consultation with works councils where they exist.
- Data minimisation: you only need actor, timestamp, event and file. Drop IP addresses if you don't need them.
FlowStatus follows the same approach. It stores activity metadata only, never file contents, and its leadership views are built around teams and projects. See how FlowStatus works.
Frequently asked questions
How do I export Figma activity logs?
Sign in as a Figma organisation admin, open Admin settings, go to the Activity tab, set a date range and any filters, and export to CSV. On the Enterprise plan you can also pull the same events programmatically from the Activity Logs REST API (GET https://api.figma.com/v1/activity_logs) with an OAuth app that has the org:activity_log_read scope.
Which Figma plan do I need for activity logs?
Organisation activity logs are an admin feature of Figma's Organization and Enterprise plans. The Activity Logs REST API is available on the Enterprise plan. Figma adjusts plan features over time, so confirm against Figma's current help centre for your contract.
What fields are in a Figma activity log export?
A Figma activity-log CSV includes a timestamp, the actor (email), the event name (for example fig_file_view or fig_file_create), and what was acted on (a name and an ID or key). Exports commonly include further context such as the type of thing acted on and IP address. For flow analysis, the timestamp, actor, event name and file key are the essential fields.
Does the Figma activity log show edits?
Not in fine detail. Activity-log CSV exports do not include an event for every edit. Views, creates, renames, moves, duplicates and exports carry the signal, so audits measure patterns of attention and file lifecycle rather than individual edits.
Can Figma activity logs show whether a design team is focused?
Yes. The sequence of file events shows whether designers sustain attention on a few files or hop between many. In the 2026 Design Telemetry Benchmark, projects with low file-switching averaged 3.1/5 on outcomes versus 2.1/5 for high switching, making it the strongest predictor among the factors examined. FlowStatus computes focus, momentum and friction from these logs automatically.
How do I find unused Figma seats from activity logs?
Join the activity log to your members list and flag paid seats with no productive actions (create, rename, move, duplicate or export) in the last 90 days. Treat the list as candidates for review, not automatic downgrades: confirm against Figma Admin seat management and talk to the people involved.
Is it legal to analyse Figma activity logs under GDPR?
Activity logs contain personal data, so UK and EU GDPR apply. Most organisations rely on legitimate interest for operational analytics, supported by a documented purpose, a legitimate interests assessment, restricted access, aggregation to team or project level, clear communication to staff and, where relevant, consultation with works councils. Take advice from your data protection officer.