Why does changing a Google Group’s nickname appear under USER_SETTINGS → ADD_NICKNAME in Admin audit logs(Report Api) instead of GROUP_SETTINGS?
02:50 06 Nov 2025

I noticed an odd behavior in the Google Workspace Admin audit logs under Report Api.

When a Google Group’s nickname (email alias) is changed, the corresponding log entry appears under:
Event type: USER_SETTINGS

Event name: ADD_NICKNAME

However, logically this action modifies a Google Group entity, not an individual user.
Therefore, I would have expected the event to fall under the event type[GROUP_SETTINGS] for consistency and easier traceability.

Here’s what I’d like to clarify:

  • Is this the expected behaviour as per Google’s audit logging design?

  • Or could this be an incorrect classification in the audit log schema or documentation?

Has anyone else observed this behaviour or found any official explanation for why nickname changes for groups are logged under USER_SETTINGS?

google-workspace audit