Skip to content

Review activity and the audit trail

Two views cover what happened in a workspace. Activity summarizes governed events in readable language, grouped by day. Settings → Audit is the complete, filterable audit trail with export.

Choose an Activity type: State changes (the default) or All activity, which also includes reads. Filter by Actor, Service ID, Workflow, and Outcome. Repeated events collapse into one row with a count.

Filter by Action, Actor, Correlation (a request, workflow, or approval identifier), Outcome, Resource type, Resource ID, Severity, and a From and To range. Every row shows the action, outcome, severity, actor, resource, timestamp, correlations, and an Evidence details section with the bounded, redacted details.

Export CSV downloads the filtered events, newest first, up to ten thousand rows. Reading or exporting the audit trail is itself recorded as an audit event.

  • Every privileged transition is recorded: approvals, denials, runner and deployment actions, policy revisions, invitations, and support grants.
  • Details are bounded and redacted at the write boundary. Credential-like fields, tokens, and email addresses are replaced before storage.
  • The trail is append-only and workspace-scoped. There is no retention purge.

See Limits and defaults for the exact bounds.