Open Audit (/audit).
Each IPAM write (prefix, subnet, pool, reservation, token, DNS record, webhook, NetBox, force-release, …) records before/after. The table is append-only. Use it when someone asks “who moved that reservation.” Occupancy (who held an IP, where a MAC has been, what sat on a switch port) is History, not Audit.
Overview also shows recent IPAM changes.
DHCP acks are not audit rows; they are lease rows and JSON logs (xid, MAC, IP). Subscribe ipam.audit on a webhook if a SIEM should see the same events.