Who changed what in your organization, when and from where.
Cloud → Audit log (under Settings) shows your organization's events, newest first. Owners and admins can read it (audit:read).
| |
|---|
| Action | What happened, such as deployment.promote. |
| Actor | Who did it: a person, a key, an agent, or the platform itself (for example the build pipeline marking a deployment ready). |
| Target | What it happened to, such as a project, deployment or key. |
| Details | A short summary, like the environments a variable applies to or the strategy a pull request was merged with. |
| From | The IP address and user agent of the request, when there was one. |
Events never contain secret values: no environment variable values, keys, tokens, job inputs or invite links, and a connector's address is recorded without its query string.
Changes to your own account (password, passkeys) appear in every organization you belong to.
- Filter by an activity (a single action or a whole category).
- Filter by an actor or a target from any event's row.
- Scroll to load older events.
- Export JSON Lines downloads the matching events, newest first, up to 10,000 at a time. Narrow the filters to export older ones.
How long events are kept depends on your organization's plan; the page says how many days. Events older than that are deleted.
Owners and admins can have each day's events copied into one of the organization's buckets: on the Audit log page, under Daily export, choose the bucket and save. After midnight UTC, the previous day's events are written to audit/<yyyy-mm-dd>.jsonl in that bucket (one event per line, oldest first, the same fields as Export JSON Lines). Only events recorded after you turn it on are exported; days already in the bucket are merged, not overwritten. Turn it off by choosing Off. What happens to the files afterwards (retention, access) is up to the bucket's settings.
| Action | Shown as |
|---|
project.create | Created project |
project.update | Updated project |
project.rename | Renamed project |
project.transfer | Transferred project |
project.delete | Deleted project |
| Action | Shown as |
|---|
deployment.start | Started deployment of |
deployment.redeploy | Redeployed |
deployment.promote | Promoted to production |
deployment.rollback | Rolled back production to |
deployment.ready | Deployed |
deployment.failed | Deployment failed |
deployment.canceled | Deployment canceled |
deployment.expire | Expired |
| Action | Shown as |
|---|
env.update | Set environment variable |
env.bulk_upsert | Set environment variables for |
env.delete | Removed environment variable |
| Action | Shown as |
|---|
domain.create | Added domain |
domain.update | Updated domain |
domain.delete | Removed domain |
domain.dns | Added DNS records in Cloudflare |
| Action | Shown as |
|---|
integration.connect | Connected integration |
integration.disconnect | Disconnected integration |
| Action | Shown as |
|---|
resource.create | Created database, bucket or repository |
resource.update | Updated database, bucket or repository |
resource.link | Linked database, bucket or repository |
resource.unlink | Unlinked database, bucket or repository |
resource.delete | Deleted database, bucket or repository |
| Action | Shown as |
|---|
pull.create | Opened pull request |
pull.merge | Merged pull request |
pull.close | Closed pull request |
pull.reopen | Reopened pull request |
pull.approve | Approved pull request |
pull.unapprove | Withdrew approval of pull request |
| Action | Shown as |
|---|
repo.create | Created repository |
repo.rename | Renamed repository |
repo.protect | Changed branch protection of |
repo.delete | Deleted repository |
repo.push | Pushed to |
| Action | Shown as |
|---|
branch.create | Created branch |
branch.delete | Deleted branch |
branch.default | Changed the default branch of |
| Action | Shown as |
|---|
file.commit | Committed to |
| Action | Shown as |
|---|
device.approve | Approved agent |
device.deny | Denied agent |
device.update | Updated agent |
device.revoke | Revoked agent |
device.host_request | Asked for a new host |
device.host_approve | Allowed a host for agent |
device.host_deny | Denied a host for agent |
| Action | Shown as |
|---|
job.create | Queued agent job |
job.cancel | Canceled agent job |
job.access_request | Asked for agent access for job |
| Action | Shown as |
|---|
connector.create | Added connector |
connector.update | Updated connector |
connector.delete | Removed connector |
connector.tool_call | Called a tool on connector |
connector.oauth_connect | Signed in to connector |
| Action | Shown as |
|---|
oauth_client.create | Added sign-in client |
oauth_client.update | Updated sign-in client |
oauth_client.rotate | Replaced the secret of sign-in client |
oauth_client.delete | Removed sign-in client |
| Action | Shown as |
|---|
integration.connect | Connected integration |
integration.disconnect | Disconnected integration |
| Action | Shown as |
|---|
page.create | Created page |
page.update | Updated page |
page.delete | Moved page to trash |
page.restore | Restored page |
| Action | Shown as |
|---|
context.update | Set context entry |
context.delete | Deleted context entry |
| Action | Shown as |
|---|
member.invite | Invited |
member.invite_revoke | Revoked invite for |
member.join | Joined organization |
| Action | Shown as |
|---|
team.create | Created team |
team.delete | Deleted team |
team.member_add | Added a member to team |
team.member_update | Changed a member's role in team |
team.member_remove | Removed a member from team |
team.grant_add | Gave write access to team |
team.grant_remove | Removed access from team |
| Action | Shown as |
|---|
key.create | Created key |
key.revoke | Revoked key |
| Action | Shown as |
|---|
account.sign_in | Signed in |
account.oauth_app_authorize | Connected app |
account.oauth_app_revoke | Removed app |
account.sign_in_failed | Failed to sign in |
account.password_change | Changed password |
account.passkey_add | Added passkey |
account.passkey_remove | Removed passkey |
account.app_password_create | Created app password |
account.app_password_revoke | Revoked app password |
account.app_password_first_use | First used app password |
account.exchange_device_remove | Removed device |
account.exchange_device_wipe | Asked a device to remove an account |
account.exchange_device_wipe_cancel | Cancelled removing an account from a device |
account.exchange_grant_create | Signed in Apple device |
account.exchange_grant_revoke | Signed out Apple device |
account.exchange_grant_reuse | Signed out Apple device after a reused refresh token |
account.exchange_signin_approve | Approved a sign-in from another device |
account.exchange_signin_deny | Denied a sign-in from another device |
account.cli_sign_in | Signed in the command line on |
account.cli_sign_out | Signed out the command line on |
| Action | Shown as |
|---|
mail.domain_create | Added mail domain |
mail.domain_update | Updated mail domain |
mail.domain_delete | Removed mail domain |
mail.mailbox_create | Created mailbox |
mail.mailbox_update | Updated mailbox |
mail.mailbox_delete | Deleted mailbox |
mail.alias_create | Added alias |
mail.alias_delete | Removed alias |
| Action | Shown as |
|---|
calendar.create | Created calendar |
calendar.update | Updated calendar |
calendar.delete | Deleted calendar |
calendar.import | Imported events into calendar |
calendar.event_create | Created event |
calendar.event_update | Updated event |
calendar.event_delete | Deleted event |
calendar.event_respond | Responded to event |
calendar.itip | Applied meeting mail to event |
| Action | Shown as |
|---|
contacts.book_create | Created address book |
contacts.book_update | Updated address book |
contacts.book_delete | Deleted address book |
contacts.import | Imported contacts into address book |
contacts.create | Created contact |
contacts.update | Updated contact |
contacts.delete | Deleted contact |
| Action | Shown as |
|---|
org.create | Created organization |
org.update | Updated organization |
org.delete | Deleted organization |
| Action | Shown as |
|---|
region.update | Updated region |
| Action | Shown as |
|---|
location.update | Updated location |
| Action | Shown as |
|---|
plan.update | Updated plan |
| Action | Shown as |
|---|
model.update | Updated model |
Sign-ins and failed sign-ins are recorded in every organization of the account. Connector tool calls record the tool's name, whether it failed and how long it took, never its arguments or results. Git pushes record the branches and tags the push asked to update.