Audit
For Owners, Operators and anyone granted a Role that reads Audit, including security and compliance teams reading after the fact: who did what, and when, in the console and by the platform on its behalf.
Read the log
Open Identity & Access Management → Audit (disabled hover: "Requires owner or operator (or an AdminManage-class grant)"). Role and tier grants, API-key lifecycle, deployment update, reconfigure, rollback, pause and resume, account regions, Library item deletions and the shared Entra credentials are kept for 400 days; deployment creation and uninstall, account registration and Library creation are on the job and object pages, not here. Rows are newest first: When, Who, Action, Target (type and id), Outcome and AWS account; the footer states the window in UTC and the list pages with Previous and Next.
Who is the administrator's email. An action through a share request reads "<actor> (via share request)"; the installer's first set-up reads "System (initial setup)".
Filter
- Filter by actor (exact email or worker id).
- From (UTC) and To (UTC) as YYYY-MM-DD; the default window is the last seven days.
- Action (exact): the full action name, for example
role.grant.created.
Filters are exact; Clear filters resets them. Nothing matching reads Nothing matches these filters; an empty window reads Nothing recorded in this window.
What you should see
| Action | What happened |
|---|---|
role.grant.created, role.grant.archived | A Role or tier granted or revoked (Users, groups and roles). |
apikey.created, apikey.updated, apikey.rotated, apikey.external_id_rotated, apikey.revoked, apikey.deleted, apikey.expired | An API key's lifecycle (Programmatic access). |
apikey.materialised, apikey.run_data_purged | The platform activated the key in its deployment; a deleted key's run data was purged (actor "AlphaAgent Organisations"). |
console_access.assigned, console_access.assignment_failed, console_access.reconciled, console_access.released, console_access.release_failed | The console-app assignment made in your Entra tenant alongside a grant, or released with a revoke. |
deployment.seat_cap.exceeded | A deployment found over its user cap (Users, groups and roles). |
deployment.upgrade.triggered, deployment.reconfigure.triggered, deployment.rollback.triggered | An update, reconfigure or rollback job started. |
deployment.ecs.pause, deployment.ecs.resume | A deployment paused or resumed. |
account.allowed_regions.updated | A region added to an AWS account. |
library.item.deleted | An item deleted from a Library. |
platform_config.entra.credentials_updated | The shared Entra credentials replaced (Identity providers). |
Notes
- Events are kept for 400 days; a window spans at most 90 days, and From after To is refused.
- No partial or wildcard search, and no export button: narrow the window and copy the rows, call
GET /audit?from&to&actor&actionon the Organisations API for the same rows as JSON (up to 200 per page, continued withcursor; Audit trails), or read the same records in your AWS account's logs. - Changes made inside a Studio deployment by its users are Studio's own records, not this log.