SISuperintelligenceDocs

Search docs

Search every page of the documentation.

Identity and access

Audit log

Who changed what in your organization, when and from where.

Cloud → Audit log (under Settings) shows your organization's events, newest first. Owners and admins can read it (audit:read).

An event

ActionWhat happened, such as deployment.promote.
ActorWho did it: a person, a key, an agent, or the platform itself (for example the build pipeline marking a deployment ready).
TargetWhat it happened to, such as a project, deployment or key.
DetailsA short summary, like the environments a variable applies to or the strategy a pull request was merged with.
FromThe IP address and user agent of the request, when there was one.

Events never contain secret values: no environment variable values, keys, tokens, job inputs or invite links, and a connector's address is recorded without its query string.

Changes to your own account (password, passkeys) appear in every organization you belong to.

Find events

  • Filter by an activity (a single action or a whole category).
  • Filter by an actor or a target from any event's row.
  • Scroll to load older events.
  • Export JSON Lines downloads the matching events, newest first, up to 10,000 at a time. Narrow the filters to export older ones.

Retention

How long events are kept depends on your organization's plan; the page says how many days. Events older than that are deleted.

Daily export

Owners and admins can have each day's events copied into one of the organization's buckets: on the Audit log page, under Daily export, choose the bucket and save. After midnight UTC, the previous day's events are written to audit/<yyyy-mm-dd>.jsonl in that bucket (one event per line, oldest first, the same fields as Export JSON Lines). Only events recorded after you turn it on are exported; days already in the bucket are merged, not overwritten. Turn it off by choosing Off. What happens to the files afterwards (retention, access) is up to the bucket's settings.

What's recorded

Projects

ActionShown as
project.createCreated project
project.updateUpdated project
project.renameRenamed project
project.transferTransferred project
project.deleteDeleted project

Deployments

ActionShown as
deployment.startStarted deployment of
deployment.redeployRedeployed
deployment.promotePromoted to production
deployment.rollbackRolled back production to
deployment.readyDeployed
deployment.failedDeployment failed
deployment.canceledDeployment canceled
deployment.expireExpired

Environment variables

ActionShown as
env.updateSet environment variable
env.bulk_upsertSet environment variables for
env.deleteRemoved environment variable

Domains

ActionShown as
domain.createAdded domain
domain.updateUpdated domain
domain.deleteRemoved domain
domain.dnsAdded DNS records in Cloudflare

Integrations

ActionShown as
integration.connectConnected integration
integration.disconnectDisconnected integration

Storage and repositories

ActionShown as
resource.createCreated database, bucket or repository
resource.updateUpdated database, bucket or repository
resource.linkLinked database, bucket or repository
resource.unlinkUnlinked database, bucket or repository
resource.deleteDeleted database, bucket or repository

Pull requests

ActionShown as
pull.createOpened pull request
pull.mergeMerged pull request
pull.closeClosed pull request
pull.reopenReopened pull request
pull.approveApproved pull request
pull.unapproveWithdrew approval of pull request

Repositories

ActionShown as
repo.createCreated repository
repo.renameRenamed repository
repo.protectChanged branch protection of
repo.deleteDeleted repository
repo.pushPushed to

Branches

ActionShown as
branch.createCreated branch
branch.deleteDeleted branch
branch.defaultChanged the default branch of

Web commits

ActionShown as
file.commitCommitted to

Agents

ActionShown as
device.approveApproved agent
device.denyDenied agent
device.updateUpdated agent
device.revokeRevoked agent
device.host_requestAsked for a new host
device.host_approveAllowed a host for agent
device.host_denyDenied a host for agent

Agent jobs

ActionShown as
job.createQueued agent job
job.cancelCanceled agent job
job.access_requestAsked for agent access for job

Connectors

ActionShown as
connector.createAdded connector
connector.updateUpdated connector
connector.deleteRemoved connector
connector.tool_callCalled a tool on connector
connector.oauth_connectSigned in to connector

Sign-in clients

ActionShown as
oauth_client.createAdded sign-in client
oauth_client.updateUpdated sign-in client
oauth_client.rotateReplaced the secret of sign-in client
oauth_client.deleteRemoved sign-in client

Integrations

ActionShown as
integration.connectConnected integration
integration.disconnectDisconnected integration

Docs

ActionShown as
page.createCreated page
page.updateUpdated page
page.deleteMoved page to trash
page.restoreRestored page

Context

ActionShown as
context.updateSet context entry
context.deleteDeleted context entry

Members

ActionShown as
member.inviteInvited
member.invite_revokeRevoked invite for
member.joinJoined organization

Teams

ActionShown as
team.createCreated team
team.deleteDeleted team
team.member_addAdded a member to team
team.member_updateChanged a member's role in team
team.member_removeRemoved a member from team
team.grant_addGave write access to team
team.grant_removeRemoved access from team

Keys

ActionShown as
key.createCreated key
key.revokeRevoked key

Sign-in methods

ActionShown as
account.sign_inSigned in
account.oauth_app_authorizeConnected app
account.oauth_app_revokeRemoved app
account.sign_in_failedFailed to sign in
account.password_changeChanged password
account.passkey_addAdded passkey
account.passkey_removeRemoved passkey
account.app_password_createCreated app password
account.app_password_revokeRevoked app password
account.app_password_first_useFirst used app password
account.exchange_device_removeRemoved device
account.exchange_device_wipeAsked a device to remove an account
account.exchange_device_wipe_cancelCancelled removing an account from a device
account.exchange_grant_createSigned in Apple device
account.exchange_grant_revokeSigned out Apple device
account.exchange_grant_reuseSigned out Apple device after a reused refresh token
account.exchange_signin_approveApproved a sign-in from another device
account.exchange_signin_denyDenied a sign-in from another device
account.cli_sign_inSigned in the command line on
account.cli_sign_outSigned out the command line on

Mail

ActionShown as
mail.domain_createAdded mail domain
mail.domain_updateUpdated mail domain
mail.domain_deleteRemoved mail domain
mail.mailbox_createCreated mailbox
mail.mailbox_updateUpdated mailbox
mail.mailbox_deleteDeleted mailbox
mail.alias_createAdded alias
mail.alias_deleteRemoved alias

Calendar

ActionShown as
calendar.createCreated calendar
calendar.updateUpdated calendar
calendar.deleteDeleted calendar
calendar.importImported events into calendar
calendar.event_createCreated event
calendar.event_updateUpdated event
calendar.event_deleteDeleted event
calendar.event_respondResponded to event
calendar.itipApplied meeting mail to event

Contacts

ActionShown as
contacts.book_createCreated address book
contacts.book_updateUpdated address book
contacts.book_deleteDeleted address book
contacts.importImported contacts into address book
contacts.createCreated contact
contacts.updateUpdated contact
contacts.deleteDeleted contact

Organizations (platform organization)

ActionShown as
org.createCreated organization
org.updateUpdated organization
org.deleteDeleted organization

Regions (platform organization)

ActionShown as
region.updateUpdated region

Locations (platform organization)

ActionShown as
location.updateUpdated location

Plans (platform organization)

ActionShown as
plan.updateUpdated plan

Models (platform organization)

ActionShown as
model.updateUpdated model

Sign-ins and failed sign-ins are recorded in every organization of the account. Connector tool calls record the tool's name, whether it failed and how long it took, never its arguments or results. Git pushes record the branches and tags the push asked to update.