Skip to content
147 linesCodeBlameRaw
1---
2title: Audit log
3description: Every action agents take with their run credentials, and every change people and tokens make, with whether it was allowed and the rule that decided.
4---
5
6Every workspace keeps an audit log. It records:
7
8- **Everything an agent does** with its [run credentials](/guides/working-with-g1t/#credentials),
9 reads included: every API and MCP call, every clone and fetch, every push.
10- **Every change people and workspace tokens make** through the API, the
11 MCP server and git: opening and closing issues, comments, merges,
12 settings, pushes. Reads by people are not recorded. A workflow job's
13 [`G1T_TOKEN`](/guides/actions/#the-jobs-token) is recorded as that job's,
14 under its run.
15
16- **A repository's lifecycle**, wherever the change was made, g1t.sh
17 included. A transfer is recorded in both workspaces' logs, and a
18 workspace's deletion as `workspace.deleted`. A restore by g1t's support
19 is recorded as `workspace.restored`, and the purge 30 days after a
20 deletion as `workspace.purged`, its log's last entry.
21
22| Action | Recorded when |
23| --- | --- |
24| `repo.renamed` | A repository was renamed. |
25| `repo.visibility_changed` | It was made public or private. |
26| `repo.default_branch_changed` | Its default branch changed. |
27| `branch.renamed` | A branch was renamed. |
28| `repo.archived`, `repo.unarchived` | It was archived, or unarchived. |
29| `repo.transferred` | It moved to another workspace. |
30| `repo.deleted`, `repo.restored`, `repo.purged` | It was deleted, restored, or removed for good. |
31| `repo.collaborator_added`, `repo.collaborator_role_changed`, `repo.collaborator_removed` | Someone was given a role on it, had it changed, or lost it. See [access and roles](/guides/access-and-roles/). |
32| `repo.invitation_created`, `repo.invitation_revoked` | Someone was invited to it, or an invitation was withdrawn. |
33| `repo.deploy_key_added`, `repo.deploy_key_removed` | A [deploy key](/guides/git/#deploy-keys) was added to it, saying whether it may write, or deleted. |
34| `workspace.base_permission_changed` | An owner changed what members get on every repository. |
35| `member.added`, `member.removed`, `member.left` | Someone joined the workspace (added by an owner, or with an invite), was removed by an owner, or left. See [members and roles](/guides/workspaces/#members-and-roles). |
36| `member.role_changed` | An owner made someone an owner or a member. |
37| `member.org_role_added`, `member.org_role_removed` | An owner made someone a billing manager or a security manager, or took it away. |
38| `workspace.ownership_transferred` | An owner handed the workspace to another member. |
39| `workspace.member_privileges_changed` | An owner turned a [member privilege](/guides/workspaces/#member-privileges) on or off. |
40| `workspace.two_factor_required`, `workspace.two_factor_not_required` | An owner started or stopped [requiring two-factor authentication](/guides/workspaces/#require-two-factor-authentication). |
41| `workspace_token.created`, `workspace_token.deleted` | An owner made or deleted one of the workspace's [access tokens](/guides/workspaces/#workspace-access-tokens). |
42| `token.created`, `token.deleted`, `token.rescoped` | A member made, deleted or changed the scopes of one of their own [access tokens](/guides/authentication/#access-tokens). Recorded in each of their workspaces. |
43| `ssh_key.added`, `ssh_key.removed` | A member added or removed an SSH key. Recorded in each of their workspaces. |
44| `oauth_grant.created`, `oauth_grant.rescoped`, `oauth_grant.revoked` | A member [signed in to an application](/guides/authentication/#signing-in-with-oauth), changed what it may do, or signed it out. Recorded in each of their workspaces. |
45| `two_factor.enabled`, `two_factor.disabled` | A member turned [two-factor authentication](/guides/authentication/#two-factor-authentication) on or off. Recorded in each of their workspaces. |
46| `token.policy_changed` | An owner changed the workspace's [rules for personal access tokens](/guides/authentication/#a-workspaces-rules-for-tokens). |
47| `token.approval_requested`, `token.approved`, `token.denied` | A member's fine-grained token asked to reach the workspace, and an owner approved or denied it, with their note. |
48| `token.revoked` | An owner revoked a member's token in the workspace, with their note. |
49| `workspace.team_creation_changed` | An owner changed who can create teams. See [who can create teams](/guides/teams/#who-can-create-teams). |
50| `team.created`, `team.edited`, `team.deleted` | A [team](/guides/teams/) was created, changed or deleted. |
51| `team.member_added`, `team.member_role_changed`, `team.member_removed` | Someone was added to a team, made its maintainer or a member, or taken out of it. |
52| `team.repo_added`, `team.repo_role_changed`, `team.repo_removed` | A team was given a role on a repository, had it changed, or lost it. |
53| `package.delete`, `package.restore`, `package.purged` | A [package](/guides/packages/#delete-and-restore) was deleted, restored, or removed for good 30 days after it was deleted. |
54| `package.delete_version`, `package.restore_version` | One of its versions was deleted or restored. |
55| `package.access_added`, `package.access_role_changed`, `package.access_removed` | A person or team was given a role on a package itself, had it changed, or lost it. |
56| `package.actions_access_added`, `package.actions_access_role_changed`, `package.actions_access_removed` | A repository's workflows were given access to a package under [Manage Actions access](/guides/packages/#manage-actions-access), had it changed, or lost it. |
57| `package.inherit_access_changed` | Inheriting access from the linked repository was turned on or off. |
58| `package.visibility_changed` | A package was made public or private. |
59| `package.linked`, `package.unlinked` | A package was linked to a repository (from its settings, or by an image's source label), or unlinked. |
60| `workspace.residency_changed` | An owner changed where the workspace's new repositories are stored. See [data residency](/guides/workspaces/#data-residency). |
61| `account.deleted`, `account.deleted_by_staff` | A member [deleted their account](/guides/authentication/#deleting-your-account), or g1t's staff deleted it, and so left the workspace. Recorded in each of their workspaces. |
62| `workspace.deleted`, `workspace.restored`, `workspace.purged` | An owner deleted the workspace (or g1t's staff did, with the [deleted account](/guides/authentication/#what-stands-in-the-way) that was its only owner), g1t's support restored it, or it was removed for good. See [deleting a workspace](/guides/workspaces/#delete-a-workspace). |
63
64Through the API and the MCP server, the call itself is recorded under its
65operation's name too, such as `delete_repo`. See
66[managing a repository](/guides/managing-repositories/).
67
68Refusals are recorded too, with the rule that refused them. Entries are
69only ever added: nothing edits or removes one.
70
71## What an entry says
72
73| Field | What it is |
74| --- | --- |
75| Time | When it happened, to the millisecond. |
76| Actor | Who did it: a person, an agent, or a workspace token. |
77| On behalf of | For an agent, the person it worked for: `g1t on behalf of syntaqx`. |
78| Run | The agent run, with its kind: `implement`, `review`, `update` and so on; or the workflow run whose job's token did it, as `workflow_job`. |
79| Credential | The id of the token used. |
80| Action | The API or MCP operation, such as `create_issue`, or `git.push` and `git.fetch`. |
81| Target | The repository, the issue or pull request number, and for git the refs it moved. |
82| Outcome | `allowed` or `denied`. |
83| Rule | What decided it: the run's scope, such as `run:implement/tools`; a refusal rule, such as `scope:repository`, or `token:repository` for a workflow job's token used on another repository; or, for people, their own access. A refusal by the repository's own rules is `service` (or `repository` for git). |
84| Result | `ok`, or the reason it failed. |
85| Request id | The request's id, the same one Cloudflare logs it under. |
86
87The rules that refuse an agent are listed under
88[credentials](/guides/working-with-g1t/#credentials).
89
90## Read the log
91
92Open the workspace's settings and choose **Audit log**, or go to
93`g1t.sh/<workspace>/-/audit`.
94
95- **Owners** see everything in the workspace.
96- **Members** see what was done to the workspace's projects, and anything
97 they did, or had done on their behalf. Changes owners made to the
98 workspace itself are for owners.
99
100Filter by actor (a person matches what they did and what agents did for
101them), agent, action, project, outcome, who acted, and a range of days.
102The filters are part of the page's address, so a filtered view can be
103shared with anyone who can see it.
104
105Each agent run's page has a **What it did** section listing its entries in
106order, and a pull request's **Agent** panel shows the latest of what its
107runs did. Both link to the full log, filtered to the run.
108
109## How long it is kept
110
111How far back the log goes depends on the workspace's plan:
112
113| Workspace | Kept |
114| --- | --- |
115| Free | **7 days** |
116| On the [g1t plan](/guides/usage-and-billing/#the-g1t-plan) | **90 days** |
117| Paid for by an [enterprise](/guides/usage-and-billing/#enterprises-and-custom-terms) | **90 days** |
118| Longer, by arrangement | Up to **400 days** |
119
120The log can be read and exported back that far, and no further. Once a
121day, entries older than that are **deleted**, and cannot be brought back:
122export what you need to keep before then. Starting the plan keeps 90 days
123from then on; entries already deleted stay deleted. Ending it goes back to
1247 days, and the next daily pass deletes what is older.
125
126For a longer log, such as for a compliance requirement, email
127[support@g1t.sh](mailto:support@g1t.sh). g1t can set the workspace's
128account to keep up to 400 days, and what is set there takes the place of
129the plan's. A [self-hosted](/guides/self-hosting/) g1t that does not charge
130keeps 90 days for every workspace.
131
132## Export
133
134**CSV** and **JSON** on the Audit log page download what the current
135filters match, up to 10,000 entries, newest first. The CSV has one column
136for each field above; a cell that a spreadsheet would read as a formula is
137written as text.
138
139## What is not recorded
140
141- Reads by people and workspace tokens.
142- Most of what people do on the website itself. The API, the MCP server
143 and git are recorded, and so are the changes to members, roles, access,
144 tokens, keys, applications, two-factor authentication and workspace
145 settings in the table above, wherever they are made.
146- What g1t does on its own, such as closing a pull request whose agent
147 failed. Those changes are in the pull request's timeline.