Identity and access
Audit log
Who changed what in your organization, when and from where.
Tenant → Audit log shows your organization's events, newest first (Cloud's old link opens it there). Owners and admins can read it (audit:read).
An event
| Action | What happened, such as deployment.promote. |
| Actor | Who did it: a person, a key, an agent, or the platform itself (for example the build pipeline marking a deployment ready). |
| Target | What it happened to, such as a Serverless App Service, deployment or key. |
| Details | A short summary, like the environments a variable applies to or the strategy a pull request was merged with. |
| From | The IP address and user agent of the request, when there was one. |
Events never contain secret values: no environment variable values, keys, tokens, job inputs or invite links, and a connector's address is recorded without its query string.
Changes to your own account (password, passkeys) appear in every organization you belong to.
Find events
- Filter by an activity (a single action or a whole category).
- Filter by an actor or a target from any event's row.
- Scroll to load older events.
- Export JSON Lines downloads the matching events, newest first, up to 10,000 at a time. Narrow the filters to export older ones.
Retention
How long events are kept depends on your organization's plan; the page says how many days. Events older than that are deleted.
Daily export
Owners and admins can have each day's events copied into one of the organization's buckets: on the Audit log page, under Daily export, choose the bucket and save. After midnight UTC, the previous day's events are written to audit/<yyyy-mm-dd>.jsonl in that bucket (one event per line, oldest first, the same fields as Export JSON Lines). Only events recorded after you turn it on are exported; days already in the bucket are merged, not overwritten. Turn it off by choosing Off. What happens to the files afterwards (retention, access) is up to the bucket's settings.
What's recorded
Serverless App Services
| Action | Shown as |
|---|---|
project.create | Created Serverless App Service |
project.update | Updated Serverless App Service |
project.rename | Renamed Serverless App Service |
project.transfer | Transferred Serverless App Service |
project.delete | Deleted Serverless App Service |
project.crons_pause | Paused cron jobs of |
project.crons_resume | Resumed cron jobs of |
project.protection_bypass_create | Created a protection bypass secret for |
project.protection_bypass_revoke | Revoked the protection bypass secret of |
Deployments
| Action | Shown as |
|---|---|
deployment.start | Started deployment of |
deployment.redeploy | Redeployed |
deployment.promote | Promoted to production |
deployment.rollback | Rolled back production to |
deployment.ready | Deployed |
deployment.failed | Deployment failed |
deployment.canceled | Deployment cancelled |
deployment.expire | Expired |
Environment variables
| Action | Shown as |
|---|---|
env.update | Set environment variable |
env.bulk_upsert | Set environment variables for |
env.delete | Removed environment variable |
env.reveal | Read development secrets of |
Secrets
| Action | Shown as |
|---|---|
secret.reveal | Read secret |
secret.restore | Restored an earlier value of secret |
secret.settings | Changed rotation and access of secret |
Domains
| Action | Shown as |
|---|---|
domain.create | Added domain |
domain.update | Updated domain |
domain.delete | Removed domain |
domain.dns | Added DNS records in Cloudflare |
Integrations
| Action | Shown as |
|---|---|
integration.connect | Connected integration |
integration.disconnect | Disconnected integration |
Storage and repositories
| Action | Shown as |
|---|---|
resource.create | Created database, bucket or repository |
resource.update | Updated database, bucket or repository |
resource.link | Linked database, bucket or repository |
resource.unlink | Unlinked database, bucket or repository |
resource.delete | Deleted database, bucket or repository |
resource.tags | Changed the tags of database, bucket or repository |
resource.group | Changed the resource group of database, bucket or repository |
Resource groups
| Action | Shown as |
|---|---|
resource_group.create | Created resource group |
resource_group.update | Updated resource group |
resource_group.delete | Deleted resource group |
Dashboards
| Action | Shown as |
|---|---|
dashboard.create | Created dashboard |
dashboard.share | Changed who sees dashboard |
dashboard.delete | Deleted dashboard |
Pull requests
| Action | Shown as |
|---|---|
pull.create | Opened pull request |
pull.merge | Merged pull request |
pull.close | Closed pull request |
pull.reopen | Reopened pull request |
pull.approve | Approved pull request |
pull.unapprove | Withdrew approval of pull request |
Repositories
| Action | Shown as |
|---|---|
repo.create | Created repository |
repo.rename | Renamed repository |
repo.protect | Changed branch protection of |
repo.delete | Deleted repository |
repo.checks | Ran checks on |
repo.push | Pushed to |
repo.access_update | Changed who can access |
repo.access_denied | Was refused access to |
repo.branch_rules_update | Changed branch rules of |
repo.push_refused | Was refused a push to |
repo.secret_allow | Allowed a detected secret in |
repo.read_audit_update | Changed read auditing of |
Branches
| Action | Shown as |
|---|---|
branch.create | Created branch |
branch.delete | Deleted branch |
branch.default | Changed the default branch of |
branch.protection_bypass | Bypassed branch protection on |
Web commits
| Action | Shown as |
|---|---|
file.commit | Committed to |
Pipelines
| Action | Shown as |
|---|---|
pipeline.dispatch | Ran workflow |
pipeline.rerun | Re-ran |
pipeline.cancel | Cancelled |
pipeline.approve | Approved a deployment of |
pipeline.reject | Rejected a deployment of |
pipeline.workflow_update | Changed workflow |
pipeline.environment_update | Changed environment |
pipeline.environment_delete | Removed environment |
pipeline.secret_update | Set pipeline secret |
pipeline.secret_delete | Removed pipeline secret |
pipeline.variable_update | Set pipeline variable |
pipeline.variable_delete | Removed pipeline variable |
pipeline.cache_delete | Removed caches of |
pipeline.artifact_delete | Removed artifact |
pipeline.runner_labels | Changed the runner labels of |
Agents
| Action | Shown as |
|---|---|
device.approve | Approved agent |
device.deny | Denied agent |
device.update | Updated agent |
device.revoke | Revoked agent |
device.host_request | Asked for a new host |
device.host_approve | Allowed a host for agent |
device.host_deny | Denied a host for agent |
Agent jobs
| Action | Shown as |
|---|---|
job.create | Queued agent job |
job.cancel | Cancelled agent job |
job.access_request | Asked for agent access for job |
Connectors
| Action | Shown as |
|---|---|
connector.create | Added connector |
connector.update | Updated connector |
connector.delete | Removed connector |
connector.tool_call | Called a tool on connector |
connector.oauth_connect | Signed in to connector |
connector.oauth_disconnect | Signed out of connector |
Sign-in clients
| Action | Shown as |
|---|---|
oauth_client.create | Added sign-in client |
oauth_client.update | Updated sign-in client |
oauth_client.rotate | Replaced the secret of sign-in client |
oauth_client.delete | Removed sign-in client |
oauth_client.assign | Gave access to app |
oauth_client.unassign | Removed access to app |
Docs
| Action | Shown as |
|---|---|
page.create | Created page |
page.update | Updated page |
page.delete | Moved page to trash |
page.restore | Restored page |
page.purge | Deleted page permanently |
Context
| Action | Shown as |
|---|---|
context.update | Set context entry |
context.delete | Deleted context entry |
Members
| Action | Shown as |
|---|---|
member.invite | Invited |
member.invite_revoke | Revoked invite for |
member.join | Joined organisation |
member.update | Changed member |
member.block | Blocked sign-in for |
member.unblock | Unblocked sign-in for |
member.sessions_revoke | Ended the sessions of |
member.remove | Removed member |
member.restore | Restored member |
member.purge | Permanently removed member |
member.escalation_refused | Was refused a privilege change to |
Groups
| Action | Shown as |
|---|---|
team.create | Created team |
team.delete | Deleted team |
team.member_add | Added a member to team |
team.member_update | Changed a member's role in team |
team.member_remove | Removed a member from team |
team.grant_add | Gave write access to team |
team.grant_remove | Removed access from team |
team.update | Updated group |
Roles
| Action | Shown as |
|---|---|
role.create | Created role |
role.update | Updated role |
role.delete | Deleted role |
role.assign | Assigned role |
role.unassign | Removed role |
Sign-in policy
| Action | Shown as |
|---|---|
policy.update | Changed the sign-in policy |
Keys
| Action | Shown as |
|---|---|
key.create | Created key |
key.revoke | Revoked key |
key.transfer | Changed the owner of key |
key.expiry_set | Set when it expires on key |
Sign-in methods
| Action | Shown as |
|---|---|
account.step_up | Confirmed it was them |
account.sign_in | Signed in |
account.create | Created a personal account |
account.oauth_app_authorize | Connected app |
account.oauth_app_revoke | Removed app |
account.sign_in_failed | Failed to sign in |
account.password_change | Changed password |
account.profile_update | Changed profile |
account.passkey_add | Added passkey |
account.passkey_remove | Removed passkey |
account.session_sign_out | Signed out a browser session |
account.app_password_create | Created app password |
account.app_password_revoke | Revoked app password |
account.app_password_first_use | First used app password |
account.exchange_device_remove | Removed device |
account.exchange_device_wipe | Asked a device to remove an account |
account.exchange_device_wipe_cancel | Cancelled removing an account from a device |
account.exchange_grant_create | Signed in Apple device |
account.exchange_grant_revoke | Signed out Apple device |
account.exchange_grant_reuse | Signed out Apple device after a reused refresh token |
account.exchange_signin_approve | Approved a sign-in from another device |
account.exchange_signin_deny | Denied a sign-in from another device |
account.cli_sign_in | Signed in the command line on |
account.cli_sign_out | Signed out the command line on |
account.mobile_sign_in | Signed in the mobile app on |
account.mobile_sign_out | Signed out the mobile app on |
account.phone_add | Added phone number |
account.phone_verify | Verified phone number |
account.phone_remove | Removed phone number |
account.phone_primary | Made phone number primary |
account.mfa_update | Changed two-step sign-in |
account.mfa_totp_enabled | Turned on an authenticator app |
account.mfa_totp_disabled | Removed the authenticator app |
account.backup_codes_regenerated | Made new backup codes |
account.backup_code_used | Signed in with a backup code |
account.sign_in_approvals_on | Turned on sign-in approvals |
account.sign_in_approvals_off | Turned off sign-in approvals |
account.sign_in_approvals_resume | Resumed paused sign-in approvals |
account.approval_device_add | Added a phone that approves sign-ins |
account.approval_device_remove | Removed a phone that approves sign-ins |
account.sign_in_approval_approve | Approved a sign-in on a phone |
account.sign_in_approval_deny | Denied a sign-in on a phone |
account.sign_out_everywhere | Signed out everywhere |
account.voice_pin_set | Set the phone assistant PIN |
account.notify_update | Changed notification settings |
account.assistant_update | Changed the phone assistant |
Notifications
| Action | Shown as |
|---|---|
notify.protocol_create | Created notification protocol |
notify.protocol_update | Updated notification protocol |
notify.protocol_delete | Deleted notification protocol |
notify.protocol_attach | Attached notification protocol |
notify.protocol_detach | Detached notification protocol |
notify.sms | Sent a text message to |
notify.call | Called |
Phone assistant
| Action | Shown as |
|---|---|
assistant.call | Talked to the phone assistant |
assistant.sms | Texted the phone assistant |
assistant.action | Phone assistant acted on |
| Action | Shown as |
|---|---|
mail.domain_create | Added mail domain |
mail.domain_update | Updated mail domain |
mail.domain_delete | Removed mail domain |
mail.dkim_rotate | Rotated DKIM key |
mail.mailbox_create | Created mailbox |
mail.mailbox_update | Updated mailbox |
mail.mailbox_delete | Deleted mailbox |
mail.alias_create | Added alias |
mail.alias_delete | Removed alias |
mail.forward_add | Added forwarding address |
mail.forward_verify | Confirmed forwarding address |
mail.forward_remove | Removed forwarding address |
Calendar
| Action | Shown as |
|---|---|
calendar.create | Created calendar |
calendar.update | Updated calendar |
calendar.delete | Deleted calendar |
calendar.import | Imported events into calendar |
calendar.event_create | Created event |
calendar.event_update | Updated event |
calendar.event_delete | Deleted event |
calendar.event_respond | Responded to event |
calendar.itip | Applied meeting mail to event |
Contacts
| Action | Shown as |
|---|---|
contacts.book_create | Created address book |
contacts.book_update | Updated address book |
contacts.book_delete | Deleted address book |
contacts.import | Imported contacts into address book |
contacts.create | Created contact |
contacts.update | Updated contact |
contacts.delete | Deleted contact |
contacts.merge | Merged contacts |
contacts.bulk_update | Changed contacts |
contacts.label_update | Renamed contact label |
contacts.label_delete | Removed contact label |
Issue spaces
| Action | Shown as |
|---|---|
space.create | Created space |
space.update | Updated space |
space.archive | Archived space |
space.restore | Restored space |
space.delete | Deleted space |
Issues
| Action | Shown as |
|---|---|
issue.create | Created issue |
issue.delete | Deleted issue |
issue.move | Moved issue |
issue.bulk | Changed issues in bulk |
issue.import | Imported issues into |
issue.export | Exported issues from |
issue.approval | Decided an approval on |
Issue configuration
| Action | Shown as |
|---|---|
issue_config.create | Created database, bucket or repository |
issue_config.update | Updated database, bucket or repository |
issue_config.delete | Deleted database, bucket or repository |
Sprints
| Action | Shown as |
|---|---|
sprint.start | Started sprint |
sprint.complete | Completed sprint |
Releases
| Action | Shown as |
|---|---|
version.release | Released version |
Maps
| Action | Shown as |
|---|---|
map_list.create | Created map |
map_list.update | Updated map |
map_list.delete | Deleted map |
Flight watches
| Action | Shown as |
|---|---|
flight_watch.create | Created flight watch |
flight_watch.update | Updated flight watch |
flight_watch.pause | Paused flight watch |
flight_watch.resume | Resumed flight watch |
flight_watch.restart | Restarted flight watch |
flight_watch.delete | Deleted flight watch |
Watch zones
| Action | Shown as |
|---|---|
incident_zone.create | Created watch zone |
incident_zone.update | Updated watch zone |
incident_zone.pause | Paused watch zone |
incident_zone.resume | Resumed watch zone |
incident_zone.delete | Deleted watch zone |
Notification groups
| Action | Shown as |
|---|---|
notify_group.create | Created notification group |
notify_group.update | Updated notification group |
notify_group.delete | Deleted notification group |
notify_group.member_add | Added a recipient to |
notify_group.member_remove | Removed a recipient from |
Alert locations
| Action | Shown as |
|---|---|
maps_location.create | Created alert location |
maps_location.update | Updated alert location |
maps_location.delete | Deleted alert location |
Maps settings
| Action | Shown as |
|---|---|
maps_settings.update | Updated Maps settings |
Shared drives
| Action | Shown as |
|---|---|
drive.create | Created shared drive |
drive.update | Updated shared drive |
drive.delete | Deleted shared drive |
drive.member_add | Added a member to |
drive.member_update | Changed a member's role in |
drive.member_remove | Removed a member from |
drive.trash_empty | Emptied the trash of |
Drive files
| Action | Shown as |
|---|---|
drive_item.create | Created database, bucket or repository |
drive_item.upload | Uploaded database, bucket or repository |
drive_item.update | Updated database, bucket or repository |
drive_item.move | Moved database, bucket or repository |
drive_item.copy | Copied database, bucket or repository |
drive_item.trash | Moved database, bucket or repository to the trash |
drive_item.restore | Restored database, bucket or repository |
drive_item.delete | Deleted database, bucket or repository forever |
drive_item.share | Shared database, bucket or repository |
drive_item.unshare | Removed access to database, bucket or repository |
drive_item.link | Changed the link to database, bucket or repository |
drive_item.transfer | Transferred ownership of database, bucket or repository |
drive_item.version_restore | Restored a version of database, bucket or repository |
drive_item.version_delete | Deleted a version of database, bucket or repository |
drive_item.comment | Commented on database, bucket or repository |
drive_item.comment_delete | Deleted a comment on database, bucket or repository |
Documents, Sheets, Slides and Video
| Action | Shown as |
|---|---|
office.file_create | Created database, bucket or repository |
office.import | Opened database, bucket or repository as a document, spreadsheet or presentation |
office.export | Downloaded database, bucket or repository in another format |
office.version_restore | Restored a version of database, bucket or repository |
office.version_name | Named a version of database, bucket or repository |
office.comment | Commented on database, bucket or repository |
office.comment_delete | Deleted a comment on database, bucket or repository |
office.template_add | Made database, bucket or repository a template |
office.template_remove | Removed database, bucket or repository from the templates |
Video
| Action | Shown as |
|---|---|
video.proxy_add | Added a proxy to database, bucket or repository |
video.transcribe | Transcribed speech into captions in database, bucket or repository |
Customer records
| Action | Shown as |
|---|---|
crm_record.create | Created database, bucket or repository |
crm_record.delete | Deleted database, bucket or repository |
crm_record.transfer | Changed the owner of database, bucket or repository |
crm_record.bulk | Changed customer records in bulk |
crm_record.convert | Converted lead |
crm_record.import | Imported customer records into |
crm_record.export | Exported customer records from |
Customers settings
| Action | Shown as |
|---|---|
crm_config.create | Created database, bucket or repository |
crm_config.update | Updated database, bucket or repository |
crm_config.delete | Deleted database, bucket or repository |
Marketing
| Action | Shown as |
|---|---|
marketing.create | Created database, bucket or repository |
marketing.update | Updated database, bucket or repository |
marketing.delete | Deleted database, bucket or repository |
marketing.import | Imported people into database, bucket or repository |
Marketing sends
| Action | Shown as |
|---|---|
marketing_send.request_approval | Asked for approval of database, bucket or repository |
marketing_send.approve | Approved database, bucket or repository |
marketing_send.decline | Declined database, bucket or repository |
marketing_send.schedule | Scheduled database, bucket or repository |
marketing_send.unschedule | Unscheduled database, bucket or repository |
marketing_send.pause | Paused database, bucket or repository |
marketing_send.resume | Resumed database, bucket or repository |
marketing_send.cancel | Cancelled database, bucket or repository |
marketing_send.publish | Published database, bucket or repository |
marketing_send.stop | Stopped database, bucket or repository |
marketing_send.test | Sent a test of database, bucket or repository |
marketing_send.enter | Put someone into database, bucket or repository |
Marketing consent
| Action | Shown as |
|---|---|
marketing_consent.update | Changed the marketing consent of |
Billing
| Action | Shown as |
|---|---|
billing.plan_change | Changed the plan to |
billing.details_update | Updated billing details for |
billing.cancel | Cancelled the subscription of |
billing.subsidy_update | Changed the platform subsidy of |
billing.checkout_start | Started a checkout for |
billing.checkout_complete | Completed a checkout for |
billing.signup_paid | Paid on the payment page for |
billing.signup_named | Gave the details for |
billing.signup_account | Made the account for |
billing.signup_complete | Finished setting up |
billing.code_apply | Added a promotion code to the subscription of |
billing.code_remove | Removed the promotion code from the subscription of |
billing.promotion_create | Created the promotion code |
billing.promotion_update | Changed the promotion code |
billing.coupon_delete | Deleted the coupon |
billing.promotion_creators_update | Changed who can create promotion codes |
Organisations (platform organization)
| Action | Shown as |
|---|---|
org.create | Created organisation |
org.update | Updated organisation |
org.delete | Deleted organisation |
org.export | Exported organisation data |
Regions (platform organization)
| Action | Shown as |
|---|---|
region.update | Updated region |
Locations (platform organization)
| Action | Shown as |
|---|---|
location.update | Updated location |
Languages (platform organization)
| Action | Shown as |
|---|---|
locales.update | Changed the languages |
Plans (platform organization)
| Action | Shown as |
|---|---|
plan.update | Updated plan |
Models (platform organization)
| Action | Shown as |
|---|---|
model.update | Updated model |
Templates (platform organization)
| Action | Shown as |
|---|---|
office_template.update | Updated a built-in template |
Fonts (platform organization)
| Action | Shown as |
|---|---|
office_font.update | Updated a font |
Video presets (platform organization)
| Action | Shown as |
|---|---|
video_preset.update | Updated a video export preset |
Flight coverage (platform organization)
| Action | Shown as |
|---|---|
flight_coverage.update | Updated flight coverage area |
flight_coverage.delete | Removed flight coverage area |
ADS-B sources (platform organization)
| Action | Shown as |
|---|---|
flight_source.update | Updated ADS-B source |
Emergency feeds (platform organization)
| Action | Shown as |
|---|---|
incident_source.update | Updated emergency feed |
incident_source.delete | Removed emergency feed |
Aircraft presets (platform organization)
| Action | Shown as |
|---|---|
aircraft_preset.update | Updated aircraft preset |
aircraft_preset.delete | Removed aircraft preset |
Mail category rules (platform organization)
| Action | Shown as |
|---|---|
mail_category_rule.update | Updated mail category rule |
mail_category_rule.delete | Removed mail category rule |
Health (platform organization)
| Action | Shown as |
|---|---|
health.metric_update | Updated the Health metric |
health.settings_update | Changed Health settings |
Profile effects (platform organization)
| Action | Shown as |
|---|---|
profile_effect.update | Updated the profile effect |
Profile badges (platform organization)
| Action | Shown as |
|---|---|
badges.settings_update | Changed the profile badges |
badges.early_supporter | Changed Early Supporter for |
Limits (platform organization)
| Action | Shown as |
|---|---|
limit.gifs_update | Changed Mirage's GIF settings |
limit.update | Changed limit |
Marketing text prices (platform organization)
| Action | Shown as |
|---|---|
sms_prices.update | Changed Marketing text prices |
Mirage social (platform organization)
| Action | Shown as |
|---|---|
social.age_record | Recorded an age check for |
social.age_correct | Corrected the date of birth of |
social.age_clear | Cleared the age check of |
social.age_settings_update | Changed the age check |
social.settings_update | Updated Mirage social settings |
social.post_remove | Removed a Mirage post |
Feedback (platform organization)
| Action | Shown as |
|---|---|
feedback.update | Triaged feedback |
feedback.convert | Turned feedback into an issue: |
feedback.delete | Deleted feedback |
Runner types (platform organization)
| Action | Shown as |
|---|---|
runner_type.update | Updated runner type |
runner_type.delete | Removed runner type |
Pipeline settings (platform organization)
| Action | Shown as |
|---|---|
pipeline_settings.update | Changed pipeline settings |
Sign-ins and failed sign-ins are recorded in every organization of the account. Connector tool calls record the tool's name, whether it failed and how long it took, never its arguments or results. Git pushes record the branches and tags the push asked to update.