Skip to content

Audit Events

Reference

Generated source hash: sha256:01af8b210344a852f262a8d5427827c5c19a5fb3a107d5378f778ae6ab2b9f65.

  • Security reviewers tracing governed decisions.
  • Operators building SIEM/export mappings.
  • Docs authors checking which audit fields are safe to mention publicly.

This page is generated from contracts/events/audit-event.schema.json. Audit events are retained decision metadata. They are not a payload archive.

Use it when a page or export needs exact event type, admin action, or required-field names. Use Audit and Deny Diagnostics for workflow behavior.

  • Required fields: event_id, timestamp, tenant_id, environment_id, event_type, request_id, client_surface_id, policy_decision, policy_version, credential_mode, outcome, redaction_status.
  • Safe orientation fields: event_id, timestamp, tenant_id, environment_id, request_id, client_session_id, policy_version, credential_mode, outcome, redaction_status.
  • 14 event types and 51 admin actions are listed from the schema.
  • tool_call.requested
  • tool_call.completed
  • tool_call.denied
  • policy_decision
  • credential_mode
  • credential_resolution
  • private_route_decision
  • upstream_call
  • connector_health
  • session_lifecycle
  • api_adapter_call
  • admin_change
  • revocation
  • authentication
  • submit_server_manifest
  • submit_api_source
  • approve_registry_item
  • reject_registry_item
  • disable_registry_item
  • archive_registry_item
  • change_registry_owner
  • manifest_validation_failed
  • update_health_status
  • publish_catalog_capability
  • submit_agent
  • approve_agent
  • disable_agent
  • create_policy_draft
  • search_audit
  • terminate_session
  • update_deployment_status
  • create_telemetry_config
  • update_telemetry_config
  • test_telemetry_config
  • disable_telemetry_config
  • create_siem_webhook
  • update_siem_webhook
  • test_siem_webhook
  • disable_siem_webhook
  • emergency_disable
  • publish_policy
  • publish_policy_version
  • archive_policy_version
  • create_credential_binding
  • update_credential_binding
  • rotate_credential_binding
  • approve_credential_binding
  • reject_credential_binding
  • disable_credential_binding
  • revoke_credential_binding
  • register_connector
  • disable_connector
  • revoke_connector
  • update_connector_health
  • rotate_connector_identity
  • create_client_surface
  • disable_client_surface
  • create_local_identity_user
  • disable_local_identity_user
  • update_local_identity_group
  • create_role_binding
  • delete_role_binding
  • create_audit_export
  • create_revocation
  • permission_denied
  • Audit records include prompts, tool payloads, request bodies, response bodies, tokens, credentials, or secret material. That is a release blocker.
  • A public page links raw evidence instead of the schema or a curated runbook.
  • SIEM/export docs add fields that are absent from the schema.
  • Deny diagnostics confirms cross-tenant or cross-environment request IDs. Unknown or stale selectors should stay safe.

Type set in Geist, Source Serif 4, and Departure Mono.