The property that matters
Entries cannot be edited or selectively deleted. An entry leaves the log only when it ages out under retention or the account is deleted. The name on an entry is saved when it is written, not looked up at read time, so renaming a member or an agent later does not rewrite history.What is recorded
Governed changes happen across every area of the platform. These are the common ones:
Each entry records the action and the area it belongs to, who did it — including who was acting
on whose behalf, where an action was taken on someone’s behalf — when, and whether it
succeeded or failed. Where an update records changed fields, the entry carries the old and the
new value for those fields.
What is not recorded
- Ordinary reads. Reading a run or listing agents is not audited, and neither is an Access explorer query — it evaluates access without changing it. Revealing an API key’s token is the notable read that is recorded.
- Message content. Chat and channel message bodies live in their own run and evidence ledgers, not here.
- Secrets, ever. Revealing an API key records that the key was revealed, never the token.
Reading the log
Entries are listed newest first. Search by action, operation, or actor, filter by area and status, and sort by the When, Action, Actor, or Status column. Open an entry for its full detail — actor, operation, status, and the recorded change. Reading the log is its own capability. The built-in Viewer, Owner, and Admin roles can read it. That lets you give someone read-only oversight without granting permission to change anything.Scope
The audit log covers your account and the governed actions available to your team.Next steps
Roles & permissions
Who can read the log, and how that is granted.
Approvals
Human decisions, and where they are recorded.
Runs & evidence
The other ledger — what an agent saw and did.
Data retention, deletion & export
How long-lived records differ from archive and account deletion.