← Security
Audit log
Every security-relevant action in your org, logged with who did it and when.
What gets logged
The audit log captures administrative and security-sensitive actions:
- Member additions, removals, and group sync
- Org setting changes
- Team creation, updates, and deletion
- Secret creation and deletion (org and repo level)
- Package visibility changes (public/private)
- Policy creation, updates, and deletion
- Step library registration and deletion
- Deploy hook management
- Security bypass activation and deactivation
- Gate bypasses
- Deploy feedback creation and deletion
What each entry contains
Every log entry records the actor (who), the action (what), the target resource, and a timestamp. Entries are immutable — they cannot be edited or deleted.
Where to find it
Admin → Audit log shows the most recent events, newest first. The log is available to all org members, not just admins — transparency is the default.
No configuration needed
Audit logging is always on. There is nothing to enable, and it cannot be turned off.