Event schema
Every audit event contains an ID, organization, action, actor type, occurrence time, creation time, and JSON objects for before values, after values, and metadata. Events can also include:
The Console table shows the occurrence time, action, actor, target, and request
ID or IP address. Open any event to inspect its available details. The audit
API returns the complete typed event, including before values, after values,
metadata, and user agent.
Event details
Open an event to review its actor, target, request context, and approved state changes. The JSON view can be copied and contains exactly the sanitized fields shown in the drawer. Action-specific values that are not approved for Console display remain omitted. Policy audit snapshots contain revision, state, ownership, management mode, and definition hash information. Use policy revision history for complete policy content.Actor types
Covered activity
Audit actions are namespaced strings such asmember.*, auth.*, sso.*,
retention.*, and mcp_registry.*. Recorded activity includes:
- Membership, role, invitation, SSO, and credential changes.
- Policy, approval, governance, and remediation decisions.
- MCP Registry servers, installations, OAuth grants, and gateway tokens.
- Integration, export destination, and delivery changes.
- Retention settings, preservation holds, and cleanup outcomes.
- Configuration publication, rollback, and endpoint operations.
Search
The Console supports:- After and before timestamps.
- Action categories.
- Actor type.
- Target type.
- Newest-first pagination with 25 events per page.
action
filter is exact unless it ends in ., in which case it matches that namespace
prefix.
Integrity
Protected organization audit events, governance evaluations, and AI control-point events are appended to an organization-scoped SHA-256 hash ledger. Each ledger entry records:- A monotonic sequence number.
- Source kind and source ID.
- Canonical schema version and payload hash.
- Previous-entry hash and current entry hash.
Proof packages
Forge can produce a bounded integrity proof package containing:- Current verification status and failures.
- Ledger entries and canonical versions.
- Checkpoints spanning sequence ranges.
- Checkpoint signatures and external anchor receipts when configured.
Retention
Audit events belong to the security-record retention class. The selected organization window is 1, 3, or 7 years, subject to the effective minimum shown in the Console. Audit-ledger proofs preserve the integrity history defined by their canonical versions even when separately retained evidence detail expires. See Privacy for retention jobs, tombstone proofs, and preservation holds.Exports
Configured Splunk, Amazon S3, and other security-export destinations can receive selected organization audit events. The Audit Log links to active destinations so their schemas, credentials, health, and delivery state can be managed separately.Related pages
Access
Review the identities and roles represented in audit events.
Privacy
Configure security-record retention and preservation holds.
Compliance
Use audit evidence in framework assessments.
Splunk
Export selected security events to Splunk.