技術ログ

How to see what ChatGPT, Claude or an MCP server changed in Odoo (Odoo 20)

公開: 2026-10-09 · 著者: GRAMSHIFT

Three places standard Odoo keeps a trace, what each one shows, and what is lost when a record is deleted

How to see what ChatGPT, Claude or an MCP server changed in Odoo (Odoo 20)

To see what ChatGPT, Claude, an MCP server or an n8n flow changed in your Odoo through the API, look in three places: the Last Updated by field of each record, the chatter of records whose fields are tracked, and the Odoo server log, which has one line per API call. Together they tell you which user changed what and when. They do not keep the previous value of most fields, they do not name the API key, and a deleted record takes its chatter history with it. Details below, checked against the Odoo 20 source and the logs of a local Odoo 20 Community server.

  • Last Updated by / Last Updated on shows the user of the last change on a record, not the API key and not earlier changes.
  • Chatter tracking shows old and new values, but only for the fields a model tracks, on models with a chatter.
  • The server log shows the time, the database, the IP address, the model and the method of each call (for example sale.order/unlink), plus the ids of deleted records, but not the values that were changed or deleted.
  • When a record is deleted, Odoo also deletes its chatter messages, tracking lines included.

1. Last Updated by and Last Updated on

Every Odoo record has two fields, Last Updated by (write_uid) and Last Updated on (write_date). Open a record, switch on developer mode, and choose Metadata from the debug (bug icon) menu, or add the two fields to a list view. They answer "who touched this last, and when".

They hold the user, because an API key signs in as its user. If you, an n8n flow and Claude Desktop all use keys of the same user, the field shows the same name for all three. And it only keeps the last change: a second write replaces the first.

2. Chatter tracking

On models with a chatter (sales orders, contacts, invoices, tasks and many more), fields marked as tracked post a line such as Status: Quotation → Sales Order when they change, with the user as author. This works for API changes too, so a tracked field changed by an agent shows up in the chatter.

Two limits matter here. Only the tracked fields appear: many fields are not tracked by default, such as the sales description of a product or the website and internal notes of a contact. And in Odoo 20 the unlink of a record with a chatter first deletes the messages linked to it (mail.thread.unlink searches mail.message by model and record and removes them). Once an agent deletes a record, its tracking history is gone with it.

3. The server log

Odoo writes one line per HTTP request to its server log. On our Odoo 20 server, an API call looked like this (process id, IP and session replaced):

2026-10-06 20:20:46,514 INFO <db> odoo.http.server: <ip> <session> - [06/Oct/2026 20:20:46] "POST /json/2/sale.order/unlink HTTP/1.1" 200 ...
2026-10-06 20:24:04,724 INFO <db> odoo.http.server: <ip> <session> - [06/Oct/2026 20:24:04] "POST /xmlrpc/2/object#res.partner.write HTTP/1.1" 200 ...

For the JSON-2 API the model and method are in the URL; for XML-RPC, Odoo 20 adds them after a #. For deletions, Odoo adds one more line with the user id and the ids of the deleted records:

odoo.models.unlink: User #2 deleted sale.order records with IDs: [27]

So the log tells you that user #2 deleted sales order 27 at 20:20 from a given IP address. It does not say what the order contained, which values an update changed, or which API key was used. If you run Odoo yourself, keep this log: it is often the only record of an API call that changed fields nobody tracks.

Which API key made the change?

Standard Odoo cannot tell you. An API key record holds its description, its scope, its creation date and its expiration date; Odoo 20 keeps no "last used" date and does not write the key into the record, the chatter or the log. The calls of a key are the calls of its user.

The free fix is organisational: give each AI tool or integration its own Odoo user and create its key under that user. Then Last Updated by and the chatter name the tool, for example "Claude Desktop (bot)" or "n8n sync". It also lets you limit what each tool may do with access rights; see Read-only Odoo API key for ChatGPT, Claude or an MCP server.

What each trace shows

Last Updated byChatter trackingServer log
Which userYes (last change only)YesUser id for deletions
Which API keyNoNoNo
Which recordsPer recordPer recordIds of deleted records
Previous valuesNoTracked fields onlyNo
Content of a deleted recordNoNo (deleted with the record)No

Keeping the previous values of API changes

If an agent writes to your Odoo every day, you want the missing columns too: the old value of each changed field, the contents of a deleted record, and the name of the key. Free audit modules exist for older versions; OCA's auditlog, for example, is published up to Odoo 19 and is set up model by model.

For Odoo 20 we built AI & API Audit Log (paid, by GRAMSHIFT, which publishes this site). Install it and API requests that create, change or delete business records are logged from the moment it is installed, with the API key name (when the client signs in with a key), the records, the previous and new values, and the values and lines of deleted records, with no setup per model. Passwords and tokens stay out of the log, and direct API calls to the log are rejected. Its page lists exactly what is covered.

How this was checked: the behaviour of Last Updated by, chatter tracking, record deletion and API keys was read in the Odoo 20 source (as of 2026-10-06); the log lines come from a local Odoo 20 Community server on 2026-10-06. This page is not affiliated with Odoo S.A. On the use of AI: this article and the module were written by Claude, an AI model, working for GRAMSHIFT; the quoted code paths and log lines were compared against the source and the saved logs.

よくある質問