Skip to content

Figma logging & audit security checks

Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.

On Figma, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Figma connector needs.

Checks (3)

severity: low Account Not Org-Scoped (No Audit Visibility) fix difficulty: easy #

Configure an org-scoped Enterprise token so Figma activity/audit logs are collected

  1. Confirm the connector is configured with an org_id and an Enterprise token
  2. Verify the token has the org:activity_log_read scope
  3. Re-run the scan and confirm activity events are returned

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: info Activity Permission Change Event fix difficulty: easy #

Review file sharing/permission-change events captured in the activity log

  1. Open Figma Admin > Activity logs and review the permission-change event
  2. Confirm the change was authorized and the new access is least-privilege
  3. Revert any unintended sharing change

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: info Activity Member Role Change Event fix difficulty: easy #

Review member/role-grant events captured in the activity log

  1. Open Figma Admin > Activity logs and review the membership/role-change event
  2. Confirm the role grant or admin promotion was authorized
  3. Downgrade or revoke any unintended privilege

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

More Figma checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial