Skip to main content

Audit

For Owners, Operators and anyone granted a Role that reads Audit, including security and compliance teams reading after the fact: who did what, and when, in the console and by the platform on its behalf.

Read the log​

Open Identity & Access Management → Audit (disabled hover: "Requires owner or operator (or an AdminManage-class grant)"). Role and tier grants, API-key lifecycle, deployment update, reconfigure, rollback, pause and resume, account regions, Library item deletions and the shared Entra credentials are kept for 400 days; deployment creation and uninstall, account registration and Library creation are on the job and object pages, not here. Rows are newest first: When, Who, Action, Target (type and id), Outcome and AWS account; the footer states the window in UTC and the list pages with Previous and Next.

Who is the administrator's email. An action through a share request reads "<actor> (via share request)"; the installer's first set-up reads "System (initial setup)".

Filter​

  • Filter by actor (exact email or worker id).
  • From (UTC) and To (UTC) as YYYY-MM-DD; the default window is the last seven days.
  • Action (exact): the full action name, for example role.grant.created.

Filters are exact; Clear filters resets them. Nothing matching reads Nothing matches these filters; an empty window reads Nothing recorded in this window.

What you should see​

ActionWhat happened
role.grant.created, role.grant.archivedA Role or tier granted or revoked (Users, groups and roles).
apikey.created, apikey.updated, apikey.rotated, apikey.external_id_rotated, apikey.revoked, apikey.deleted, apikey.expiredAn API key's lifecycle (Programmatic access).
apikey.materialised, apikey.run_data_purgedThe platform activated the key in its deployment; a deleted key's run data was purged (actor "AlphaAgent Organisations").
console_access.assigned, console_access.assignment_failed, console_access.reconciled, console_access.released, console_access.release_failedThe console-app assignment made in your Entra tenant alongside a grant, or released with a revoke.
deployment.seat_cap.exceededA deployment found over its user cap (Users, groups and roles).
deployment.upgrade.triggered, deployment.reconfigure.triggered, deployment.rollback.triggeredAn update, reconfigure or rollback job started.
deployment.ecs.pause, deployment.ecs.resumeA deployment paused or resumed.
account.allowed_regions.updatedA region added to an AWS account.
library.item.deletedAn item deleted from a Library.
platform_config.entra.credentials_updatedThe shared Entra credentials replaced (Identity providers).

Notes​

  • Events are kept for 400 days; a window spans at most 90 days, and From after To is refused.
  • No partial or wildcard search, and no export button: narrow the window and copy the rows, call GET /audit?from&to&actor&action on the Organisations API for the same rows as JSON (up to 200 per page, continued with cursor; Audit trails), or read the same records in your AWS account's logs.
  • Changes made inside a Studio deployment by its users are Studio's own records, not this log.