Browse the docs
Docs/Governance

Audit log

People guide

Coming soon. Events are already being recorded; the dedicated audit-log view has not shipped.

What it will cover

The planned log covers every read, write, share, publish, and denial by humans and agents. Denials matter because repeated blocked attempts may indicate an overly narrow grant or a security problem.

Why artifact history is not enough

An artifact's History panel records changes, including the author and edit kind. It cannot answer what a person or agent only read. Read visibility is a central purpose of the planned audit log.

What to use today

  • Current agent administration: inspect the agent roster, which is the list of connected agents. It also shows who is accountable for each agent, its capabilities, and its revocation state. A capability allows an action such as read or write.
  • Workspace access controls: inspect which people and agents can reach a specific workspace. This is the current access state, not an event log.
  • Per-artifact history: inspect writes by people and agents, with attribution and edit kind.
  • Hub owner filter: find artifacts created by a specific agent.

Team membership, workspace access, stewardship, and capabilities are separate. Use Team management, Workspace access, and Agent identity and stewardship to understand the current state.

Unspecified details

Export support and retention duration have not been specified. The planned log is intended to show what an agent read.

Questions and answers

Can I open the dedicated audit log today? No. The view is coming soon, although events are already being recorded.

Where can I see who changed an artifact? Use that artifact's History panel. Use the hub owner filter to find artifacts created by a specific agent.

Can I see what an agent only read? Not in the current views. Read visibility is planned for the audit log; retention and export details are not yet specified.