Skip to content

Audit events

This page is generated from code by npm run docs:reference. Do not edit it by hand.

Payload columns list the main keys. Conditional keys and additional caller data may also be present. Entity IDs identify the internal target.

event When recorded entity Main payload keys
admin.delegation_updated Administrative action: Records a delegation configuration change. organization:<id> source_event, target
admin.email_domains_updated Administrative action: Recorded when allowed email domains change. organization:<id> current, previous
admin.invite_rejected Administrative action: Recorded when an invitation to a disallowed email domain is rejected. organization:<id> reason
admin.ip_allowlist_updated Administrative action: Recorded when the IP allowlist changes. organization:<id> current, previous
admin.ip_denied Administrative action: Recorded when the IP policy denies access. organization:<id> client_ip, ip, path
admin.role_changed Administrative action: Recorded when a role changes. organization:<id> source_event, target
approval.card_sent Approval delivery: Recorded when an approval card is delivered. request:<id> channel, message_id, slack_user_id, step_id, step_no, ts, user_id
approval.escalated Approval delivery: Recorded when approval waiting time exceeds the configured threshold and escalation is evaluated. request:<id> elapsed_hours, escalate_after_hours, escalate_to, escalated_step_id, escalated_to_group_key, escalated_to_name, escalated_to_user_id, request_id, step_id, step_no
approval.reminded Approval delivery: Recorded when an approval reminder is scheduled. request:<id> approver_group_key, elapsed_hours, recipient_user_ids, recipients, reminder_count, request_id, requester_notified, step_id
approval.slack_notify_failed Approval delivery: Records a Slack delivery failure. request:<id> change_index, reason, request_id, step_id
approval.web_notify_failed Approval delivery: Records a delivery failure originating from the web app. request:<id> detail, reason, request_id, step_id
approver_group.created Approver group: Recorded on creation. approver_group:<id> approver_group_id, key, member_count
approver_group.deleted Approver group: Recorded on deletion. approver_group:<id> approver_group_id, key, member_count
approver_group.updated Approver group: Recorded on update. approver_group:<id> approver_group_id, key, member_count, previous_member_count
attachment.added Attachment: Recorded on addition. attachment:<id> file_name, request_id, sha256, size_bytes
attachment.downloaded Attachment: Recorded on download from the workspace. attachment:<id> file_name, request_id, sha256
auth.domain_rejected Authentication: Recorded when a domain policy rejects sign-in. user:<id> {}
auth.failed Authentication: Recorded when processing fails. organization:<id>
user:<id>
channel, connection_id, reason
auth.login Authentication: Recorded on sign-in. organization:<id>
user:<id>
channel, connection_id
auth.logout Authentication: Recorded on sign-out. user:<id> channel
auth.magic_link_sent Authentication: Recorded when a sign-in link is sent. user:<id> {}
auth.sessions_revoked Authentication: Recorded when sessions are revoked. user:<id> channel
catalog.created Catalog: Recorded on creation. catalog:<id> catalog_id, key
catalog.disabled Catalog: Recorded on disabling. catalog:<id> catalog_id, key
catalog.updated Catalog: Recorded on update. catalog:<id> catalog_id, key, previous_key
cloud_account.connection_tested Cloud account: Records the result of a connection test. cloud_account:<id> key, outcome
cloud_account.created Cloud account: Recorded on creation. cloud_account:<id> key, outcome
cloud_account.deleted Cloud account: Recorded on deletion. cloud_account:<id> key, outcome
cloud_account.updated Cloud account: Recorded on update. cloud_account:<id> key, outcome
comment.added Comment: Recorded on addition. comment:<id> length, request_id, visibility
declaration.confirmed Declaration: Recorded when a declaration is confirmed after its deadline. declaration:<id> declaration_id
declaration.created Declaration: Recorded on creation. declaration:<id> declaration_id
declaration.vetoed Declaration: Recorded when a manager vetoes a declaration. declaration:<id> declaration_id, reason
delegation.created Approval delegation: Recorded on creation. delegation:<id> delegate_user_id, delegation_id, delegator_user_id, ends_at, starts_at
delegation.revoked Approval delegation: Recorded when revocation is committed. delegation:<id> delegate_user_id, delegation_id, delegator_user_id
execution.failed Execution: Recorded when processing fails. request:<id> change_index, reason, request_id
execution.fell_back Execution: Recorded when execution falls back to a manual task. request:<id> change_index, from, reason, request_id, to
execution.started Execution: Recorded when processing starts. request:<id> executor, request_id
execution.succeeded Execution: Recorded when processing succeeds. request:<id> change_count, executor, grant_count, note, request_id
grant.created Grant: Recorded on creation. grant:<id> change_index, grant_id, kind, request_id, resource
grant.expired_revoked Grant: Recorded when expiry revocation is committed. grant:<id> executor, grant_id, mode, note, request_id
grant.revoke_fell_back Grant: Recorded when revocation falls back to a manual task. grant:<id> executor, grant_id, reason, request_id, to
grant.revoked Grant: Recorded when revocation is committed. grant:<id> grant_id, reason, request_id, resource
manual.completed Manual task: Recorded when a manual task is completed with evidence. request:<id> change_index, request_id
member.department_updated Member: Recorded when the department changes. user:<id> department, member_id, previous_department
member.manager_updated Member: Recorded when the manager changes. user:<id> manager_id, member_id, previous_manager_id
notification.failed Notification: Recorded when processing fails. request:<id> / grant:<id> / report_subscription:<id> / stamp_candidate:<id>
user:<id>
kind, reason, user_id
notification.sent Notification: Recorded when a notification is delivered. request:<id> / grant:<id> / report_subscription:<id> / stamp_candidate:<id> channel, kind, message_id, user_id
operation.aborted Cloud operation: Recorded when a runbook is aborted. request:<id> step_key
operation.assessment_run Cloud operation: Recorded when a pre-execution assessment is saved. request:<id> actions, read_calls, source, trigger, verdict
operation.step_failed Cloud operation: Records a runbook step failure. request:<id> action, exit_code, message_key, output_excerpt, params, step_key
operation.step_recorded Cloud operation: Recorded when an assignee submits manual execution evidence. request:<id> action, exit_code, message_key, output_excerpt, params, step_key
operation.step_started Cloud operation: Records the start of a runbook step. request:<id> action, exit_code, message_key, output_excerpt, params, step_key
operation.step_succeeded Cloud operation: Records a successful runbook step. request:<id> action, exit_code, message_key, output_excerpt, params, step_key
plan.created Execution plan: Recorded on creation. plan:<id> catalog_keys, content_hash, request_id
plan.hash_mismatch Execution plan: Recorded when the approved plan hash does not match the execution plan hash. request:<id> content_hash, provided_hash, request_id, step_id
request.created Request: Recorded on creation. request:<id> catalog_key, catalog_keys, resubmitted_from
request.returned Request: Recorded when a request is returned with a reason. request:<id> actor, reason, request_id, step_id
request.withdrawn Request: Recorded when the requester withdraws a request. request:<id> request_id
sso.connection_activated SSO: Recorded when a connection is activated. identity_connection:<id> changed_fields, connection_id, current, preset, previous
sso.connection_created SSO: Recorded when a connection is created. identity_connection:<id> changed_fields, connection_id, current, preset, previous, secret_replaced, test_reset
sso.connection_disabled SSO: Recorded when a connection is disabled. identity_connection:<id> changed_fields, connection_id, current, preset, previous
sso.connection_tested SSO: Records the result of a connection test. identity_connection:<id> connection_id, preset, result
sso.connection_updated SSO: Recorded when a connection changes. identity_connection:<id> changed_fields, connection_id, current, preset, previous, test_reset
sso.domain_added SSO: Recorded when a domain is added for verification. organization:<id> domain
sso.domain_removed SSO: Recorded when a domain is removed. organization:<id> domain
sso.domain_verified SSO: Recorded when DNS domain verification succeeds. organization:<id> domain, result
sso.enforced SSO: Recorded when mandatory SSO is enabled. organization:<id> {}
sso.identity_linked SSO: Recorded when an external identity is linked. user:<id> connection_id, preset, user_id
sso.identity_unlinked SSO: Recorded when an external identity is unlinked. user:<id> connection_id, preset, user_id
sso.owner_bypass SSO: Recorded when an owner uses the email recovery sign-in. user:<id> user_id
sso.unenforced SSO: Recorded when mandatory SSO is disabled. organization:<id> {}
sso.user_provisioned SSO: Recorded when SSO provisions a user. user:<id> preset, user_id
stamp.promoted Stamp: Recorded when a stamp is promoted to a request. stamp:<id> catalog_key, request_id, stamp_id
stamp.recorded Stamp: Recorded when an approval reaction is saved. stamp:<id> author_id, channel_id, message_ts, stamp_id
step.approved Approval step: Recorded on approval. request:<id> plan_hash, request_id, step_id, step_no
step.rejected Approval step: Recorded on rejection. request:<id> plan_hash, request_id, step_id, step_no
user.disabled User: Recorded on disabling. user:<id> {}
user.invited User: Recorded when a user is invited. user:<id> owner
user.linked_slack User: Recorded when a Slack identity is linked to an existing user. user:<id> slack_user_id, user_id
user.locale_updated User: Recorded when the display language changes. user:<id> locale, user_id
user.merged User: Recorded when users are merged. user:<id> actor, source_user_id, target_user_id
user.role_changed User: Recorded when a role changes. user:<id> member_id, previous_role, role