← Security

Audit log

Every security-relevant action in your org, logged with who did it and when.

What gets logged

The audit log captures administrative and security-sensitive actions:

  • Member additions, removals, and group sync
  • Org setting changes
  • Team creation, updates, and deletion
  • Secret creation and deletion (org and repo level)
  • Package visibility changes (public/private)
  • Policy creation, updates, and deletion
  • Step library registration and deletion
  • Deploy hook management
  • Security bypass activation and deactivation
  • Gate bypasses
  • Deploy feedback creation and deletion

What each entry contains

Every log entry records the actor (who), the action (what), the target resource, and a timestamp. Entries are immutable — they cannot be edited or deleted.

Where to find it

Admin → Audit log shows the most recent events, newest first. The log is available to all org members, not just admins — transparency is the default.

No configuration needed

Audit logging is always on. There is nothing to enable, and it cannot be turned off.