Audit events
This page is generated from code by npm run docs:reference. Do not edit it by hand.
Reference
Section titled “Reference”Payload columns list the main keys. Conditional keys and additional caller data may also be present. Entity IDs identify the internal target.
| event | When recorded | entity | Main payload keys |
|---|---|---|---|
admin.delegation_updated |
Administrative action: Records a delegation configuration change. | organization:<id> |
source_event, target |
admin.email_domains_updated |
Administrative action: Recorded when allowed email domains change. | organization:<id> |
current, previous |
admin.invite_rejected |
Administrative action: Recorded when an invitation to a disallowed email domain is rejected. | organization:<id> |
reason |
admin.ip_allowlist_updated |
Administrative action: Recorded when the IP allowlist changes. | organization:<id> |
current, previous |
admin.ip_denied |
Administrative action: Recorded when the IP policy denies access. | organization:<id> |
client_ip, ip, path |
admin.role_changed |
Administrative action: Recorded when a role changes. | organization:<id> |
source_event, target |
approval.card_sent |
Approval delivery: Recorded when an approval card is delivered. | request:<id> |
channel, message_id, slack_user_id, step_id, step_no, ts, user_id |
approval.escalated |
Approval delivery: Recorded when approval waiting time exceeds the configured threshold and escalation is evaluated. | request:<id> |
elapsed_hours, escalate_after_hours, escalate_to, escalated_step_id, escalated_to_group_key, escalated_to_name, escalated_to_user_id, request_id, step_id, step_no |
approval.reminded |
Approval delivery: Recorded when an approval reminder is scheduled. | request:<id> |
approver_group_key, elapsed_hours, recipient_user_ids, recipients, reminder_count, request_id, requester_notified, step_id |
approval.slack_notify_failed |
Approval delivery: Records a Slack delivery failure. | request:<id> |
change_index, reason, request_id, step_id |
approval.web_notify_failed |
Approval delivery: Records a delivery failure originating from the web app. | request:<id> |
detail, reason, request_id, step_id |
approver_group.created |
Approver group: Recorded on creation. | approver_group:<id> |
approver_group_id, key, member_count |
approver_group.deleted |
Approver group: Recorded on deletion. | approver_group:<id> |
approver_group_id, key, member_count |
approver_group.updated |
Approver group: Recorded on update. | approver_group:<id> |
approver_group_id, key, member_count, previous_member_count |
attachment.added |
Attachment: Recorded on addition. | attachment:<id> |
file_name, request_id, sha256, size_bytes |
attachment.downloaded |
Attachment: Recorded on download from the workspace. | attachment:<id> |
file_name, request_id, sha256 |
auth.domain_rejected |
Authentication: Recorded when a domain policy rejects sign-in. | user:<id> |
{} |
auth.failed |
Authentication: Recorded when processing fails. | organization:<id>user:<id> |
channel, connection_id, reason |
auth.login |
Authentication: Recorded on sign-in. | organization:<id>user:<id> |
channel, connection_id |
auth.logout |
Authentication: Recorded on sign-out. | user:<id> |
channel |
auth.magic_link_sent |
Authentication: Recorded when a sign-in link is sent. | user:<id> |
{} |
auth.sessions_revoked |
Authentication: Recorded when sessions are revoked. | user:<id> |
channel |
catalog.created |
Catalog: Recorded on creation. | catalog:<id> |
catalog_id, key |
catalog.disabled |
Catalog: Recorded on disabling. | catalog:<id> |
catalog_id, key |
catalog.updated |
Catalog: Recorded on update. | catalog:<id> |
catalog_id, key, previous_key |
cloud_account.connection_tested |
Cloud account: Records the result of a connection test. | cloud_account:<id> |
key, outcome |
cloud_account.created |
Cloud account: Recorded on creation. | cloud_account:<id> |
key, outcome |
cloud_account.deleted |
Cloud account: Recorded on deletion. | cloud_account:<id> |
key, outcome |
cloud_account.updated |
Cloud account: Recorded on update. | cloud_account:<id> |
key, outcome |
comment.added |
Comment: Recorded on addition. | comment:<id> |
length, request_id, visibility |
declaration.confirmed |
Declaration: Recorded when a declaration is confirmed after its deadline. | declaration:<id> |
declaration_id |
declaration.created |
Declaration: Recorded on creation. | declaration:<id> |
declaration_id |
declaration.vetoed |
Declaration: Recorded when a manager vetoes a declaration. | declaration:<id> |
declaration_id, reason |
delegation.created |
Approval delegation: Recorded on creation. | delegation:<id> |
delegate_user_id, delegation_id, delegator_user_id, ends_at, starts_at |
delegation.revoked |
Approval delegation: Recorded when revocation is committed. | delegation:<id> |
delegate_user_id, delegation_id, delegator_user_id |
execution.failed |
Execution: Recorded when processing fails. | request:<id> |
change_index, reason, request_id |
execution.fell_back |
Execution: Recorded when execution falls back to a manual task. | request:<id> |
change_index, from, reason, request_id, to |
execution.started |
Execution: Recorded when processing starts. | request:<id> |
executor, request_id |
execution.succeeded |
Execution: Recorded when processing succeeds. | request:<id> |
change_count, executor, grant_count, note, request_id |
grant.created |
Grant: Recorded on creation. | grant:<id> |
change_index, grant_id, kind, request_id, resource |
grant.expired_revoked |
Grant: Recorded when expiry revocation is committed. | grant:<id> |
executor, grant_id, mode, note, request_id |
grant.revoke_fell_back |
Grant: Recorded when revocation falls back to a manual task. | grant:<id> |
executor, grant_id, reason, request_id, to |
grant.revoked |
Grant: Recorded when revocation is committed. | grant:<id> |
grant_id, reason, request_id, resource |
manual.completed |
Manual task: Recorded when a manual task is completed with evidence. | request:<id> |
change_index, request_id |
member.department_updated |
Member: Recorded when the department changes. | user:<id> |
department, member_id, previous_department |
member.manager_updated |
Member: Recorded when the manager changes. | user:<id> |
manager_id, member_id, previous_manager_id |
notification.failed |
Notification: Recorded when processing fails. | request:<id> / grant:<id> / report_subscription:<id> / stamp_candidate:<id>user:<id> |
kind, reason, user_id |
notification.sent |
Notification: Recorded when a notification is delivered. | request:<id> / grant:<id> / report_subscription:<id> / stamp_candidate:<id> |
channel, kind, message_id, user_id |
operation.aborted |
Cloud operation: Recorded when a runbook is aborted. | request:<id> |
step_key |
operation.assessment_run |
Cloud operation: Recorded when a pre-execution assessment is saved. | request:<id> |
actions, read_calls, source, trigger, verdict |
operation.step_failed |
Cloud operation: Records a runbook step failure. | request:<id> |
action, exit_code, message_key, output_excerpt, params, step_key |
operation.step_recorded |
Cloud operation: Recorded when an assignee submits manual execution evidence. | request:<id> |
action, exit_code, message_key, output_excerpt, params, step_key |
operation.step_started |
Cloud operation: Records the start of a runbook step. | request:<id> |
action, exit_code, message_key, output_excerpt, params, step_key |
operation.step_succeeded |
Cloud operation: Records a successful runbook step. | request:<id> |
action, exit_code, message_key, output_excerpt, params, step_key |
plan.created |
Execution plan: Recorded on creation. | plan:<id> |
catalog_keys, content_hash, request_id |
plan.hash_mismatch |
Execution plan: Recorded when the approved plan hash does not match the execution plan hash. | request:<id> |
content_hash, provided_hash, request_id, step_id |
request.created |
Request: Recorded on creation. | request:<id> |
catalog_key, catalog_keys, resubmitted_from |
request.returned |
Request: Recorded when a request is returned with a reason. | request:<id> |
actor, reason, request_id, step_id |
request.withdrawn |
Request: Recorded when the requester withdraws a request. | request:<id> |
request_id |
sso.connection_activated |
SSO: Recorded when a connection is activated. | identity_connection:<id> |
changed_fields, connection_id, current, preset, previous |
sso.connection_created |
SSO: Recorded when a connection is created. | identity_connection:<id> |
changed_fields, connection_id, current, preset, previous, secret_replaced, test_reset |
sso.connection_disabled |
SSO: Recorded when a connection is disabled. | identity_connection:<id> |
changed_fields, connection_id, current, preset, previous |
sso.connection_tested |
SSO: Records the result of a connection test. | identity_connection:<id> |
connection_id, preset, result |
sso.connection_updated |
SSO: Recorded when a connection changes. | identity_connection:<id> |
changed_fields, connection_id, current, preset, previous, test_reset |
sso.domain_added |
SSO: Recorded when a domain is added for verification. | organization:<id> |
domain |
sso.domain_removed |
SSO: Recorded when a domain is removed. | organization:<id> |
domain |
sso.domain_verified |
SSO: Recorded when DNS domain verification succeeds. | organization:<id> |
domain, result |
sso.enforced |
SSO: Recorded when mandatory SSO is enabled. | organization:<id> |
{} |
sso.identity_linked |
SSO: Recorded when an external identity is linked. | user:<id> |
connection_id, preset, user_id |
sso.identity_unlinked |
SSO: Recorded when an external identity is unlinked. | user:<id> |
connection_id, preset, user_id |
sso.owner_bypass |
SSO: Recorded when an owner uses the email recovery sign-in. | user:<id> |
user_id |
sso.unenforced |
SSO: Recorded when mandatory SSO is disabled. | organization:<id> |
{} |
sso.user_provisioned |
SSO: Recorded when SSO provisions a user. | user:<id> |
preset, user_id |
stamp.promoted |
Stamp: Recorded when a stamp is promoted to a request. | stamp:<id> |
catalog_key, request_id, stamp_id |
stamp.recorded |
Stamp: Recorded when an approval reaction is saved. | stamp:<id> |
author_id, channel_id, message_ts, stamp_id |
step.approved |
Approval step: Recorded on approval. | request:<id> |
plan_hash, request_id, step_id, step_no |
step.rejected |
Approval step: Recorded on rejection. | request:<id> |
plan_hash, request_id, step_id, step_no |
user.disabled |
User: Recorded on disabling. | user:<id> |
{} |
user.invited |
User: Recorded when a user is invited. | user:<id> |
owner |
user.linked_slack |
User: Recorded when a Slack identity is linked to an existing user. | user:<id> |
slack_user_id, user_id |
user.locale_updated |
User: Recorded when the display language changes. | user:<id> |
locale, user_id |
user.merged |
User: Recorded when users are merged. | user:<id> |
actor, source_user_id, target_user_id |
user.role_changed |
User: Recorded when a role changes. | user:<id> |
member_id, previous_role, role |