Hi @Richard Long ,
Global administrators, security administrators, or SharePoint administrators can allow or block custom scripting capabilities for the entire organization or for specific site collections. Any user who has "Add and Customize Pages" permission (part of the Design and Full Control permission levels) to any page or document library can insert code that can potentially have a powerful effect on all users and resources in the organization. Only site-collection owners can run audit log reports. SharePoint administrators can directly download data from the Microsoft 365 Management Activity API.
Reference: Security considerations of allowing custom script
Configure audit data for a site collection
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.