Review activity and the audit trail
Two views cover what happened in a workspace. Activity summarizes governed events in readable language, grouped by day. Settings → Audit is the complete, filterable audit trail with export.
Activity
Section titled “Activity”Choose an Activity type: State changes (the default) or All activity, which also includes reads. Filter by Actor, Service ID, Workflow, and Outcome. Repeated events collapse into one row with a count.
Audit trail
Section titled “Audit trail”Filter by Action, Actor, Correlation (a request, workflow, or approval identifier), Outcome, Resource type, Resource ID, Severity, and a From and To range. Every row shows the action, outcome, severity, actor, resource, timestamp, correlations, and an Evidence details section with the bounded, redacted details.
Export CSV downloads the filtered events, newest first, up to ten thousand rows. Reading or exporting the audit trail is itself recorded as an audit event.
What is and is not in the trail
Section titled “What is and is not in the trail”- Every privileged transition is recorded: approvals, denials, runner and deployment actions, policy revisions, invitations, and support grants.
- Details are bounded and redacted at the write boundary. Credential-like fields, tokens, and email addresses are replaced before storage.
- The trail is append-only and workspace-scoped. There is no retention purge.
See Limits and defaults for the exact bounds.