Skip to content
204 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1import { Download, Filter } from "lucide-react";
2import { Form, Link, data } from "react-router";
3
4import type { Route } from "./+types/audit";
5import { page } from "../../lib/meta";
6import { AuditTable } from "../../components/audit";
7import { Button, ButtonLink, EmptyState, Field, Input } from "../../components/ui";
Chat controls, public profiles, shadcn selects, and no Docs tab in a project8import { SelectField } from "../../components/ui/select";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API9import { type AuditFilters, filterHref, parseFilters, toQuery } from "../../lib/audit";
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put10import { auditPage, auditRetention } from "../../lib/audit.server";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API11import { repos } from "../../lib/services.server";
12import { requireUser, roleIn } from "../../lib/session.server";
13
14const PAGE_SIZE = 100;
15
16/** Actions worth offering in the filter; any other can be typed. */
17const COMMON_ACTIONS = [
18 "git.push",
19 "git.fetch",
20 "create_issue",
21 "add_comment",
22 "record_session",
23 "mark_pull_request_ready",
24 "review_pull_request",
25 "merge_pull_request",
26 "remember",
27 "message_agent",
28];
29
30export function meta({ params, ...args }: Route.MetaArgs) {
31 return page(args, { title: `Audit log · ${params.owner} · g1t` });
32}
33
34export async function loader({ params, context, request }: Route.LoaderArgs) {
35 const viewer = requireUser(context, request);
36 const workspace = params.owner.toLowerCase();
37 const role = roleIn(viewer, workspace);
38 if (!role) throw data("Only members of this workspace can read its audit log.", { status: 404 });
39 const filters = parseFilters(new URL(request.url).searchParams);
40 const { visibility: _, ...query } = toQuery(workspace, { kind: "all" }, filters, PAGE_SIZE);
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put41 const [found, projects, retention] = await Promise.all([
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API42 auditPage(viewer, query),
43 repos.list(viewer, { namespace: workspace }).catch(() => []),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put44 auditRetention(workspace),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API45 ]);
46 return {
47 workspace,
48 role,
49 filters,
50 entries: found?.entries ?? [],
51 next: found?.next ?? null,
52 projects: projects.map((repo) => repo.name),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put53 retention,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API54 };
55}
56
57function FilterField({
58 label,
59 name,
60 value,
61 placeholder,
62 list,
63}: {
64 label: string;
65 name: keyof AuditFilters;
66 value: string;
67 placeholder?: string;
68 list?: string;
69}) {
70 return (
71 <Field label={label}>
72 <Input name={name} defaultValue={value} placeholder={placeholder} list={list} />
73 </Field>
74 );
75}
76
Chat controls, public profiles, shadcn selects, and no Docs tab in a project77/** As tall as the inputs beside it. */
78const SELECT = "h-auto py-2";
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API79
80export default function WorkspaceAudit({ loaderData }: Route.ComponentProps) {
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put81 const { workspace, role, filters, entries, next, projects, retention } = loaderData;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API82 const base = `/${workspace}/-/audit`;
83 const filtered = Object.entries(filters).some(([key, value]) => key !== "before" && value);
84 const exportHref = (format: "csv" | "json") => filterHref(`${base}/export`, { ...filters, before: "" }) + `${filtered ? "&" : "?"}format=${format}`;
85 return (
86 <div>
87 <p className="max-w-3xl text-sm text-muted">
88 Every action taken with an agent run's credentials, reads included, and every change people and
89 workspace tokens make through the API, MCP and git: who did it, on whose behalf, with which
90 credential, to what, and whether it was allowed. Refusals name the rule that refused them.
91 {role === "owner"
92 ? " As an owner you see the whole workspace."
93 : " As a member you see what was done to the workspace's projects, and what was done by you or on your behalf."}
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put94 {retention != null &&
Audit logs are kept by plan: a week on free, 90 days on the plan, and what staff set for an account in sudo95 ` The log goes back ${retention} days, and exports the same; older entries are deleted each day.`}
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API96 </p>
97
98 <Form method="get" className="mt-6 rounded-xl border border-line bg-surface p-4">
99 <div className="grid gap-4 sm:grid-cols-2 lg:grid-cols-4">
100 <FilterField label="Actor" name="actor" value={filters.actor} placeholder="A person, or whom an agent worked for" />
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent101 <FilterField label="Agent" name="agent" value={filters.agent} placeholder="g1t" />
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API102 <FilterField label="Action" name="action" value={filters.action} placeholder="git.push" list="audit-actions" />
103 <FilterField label="Project" name="project" value={filters.project} placeholder="Any" list="audit-projects" />
104 <Field label="Outcome">
Chat controls, public profiles, shadcn selects, and no Docs tab in a project105 <SelectField
106 key={`outcome-${filters.outcome}`}
107 name="outcome"
108 defaultValue={filters.outcome}
109 className={SELECT}
110 options={[
111 { value: "", label: "Any" },
112 { value: "allowed", label: "Allowed" },
113 { value: "denied", label: "Denied" },
114 ]}
115 />
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API116 </Field>
117 <Field label="Who">
Chat controls, public profiles, shadcn selects, and no Docs tab in a project118 <SelectField
119 key={`kind-${filters.kind}`}
120 name="kind"
121 defaultValue={filters.kind}
122 className={SELECT}
123 options={[
124 { value: "", label: "Anyone" },
125 { value: "agent", label: "Agents" },
126 { value: "person", label: "People" },
127 { value: "workspace", label: "Workspace tokens" },
128 ]}
129 />
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API130 </Field>
131 <Field label="From">
132 <Input type="date" name="from" defaultValue={filters.from} />
133 </Field>
134 <Field label="To">
135 <Input type="date" name="to" defaultValue={filters.to} />
136 </Field>
137 </div>
138 {filters.run && <input type="hidden" name="run" value={filters.run} />}
139 <datalist id="audit-actions">
140 {COMMON_ACTIONS.map((action) => (
141 <option key={action} value={action} />
142 ))}
143 </datalist>
144 <datalist id="audit-projects">
145 {projects.map((name) => (
146 <option key={name} value={name} />
147 ))}
148 </datalist>
149 <div className="mt-4 flex flex-wrap items-center gap-3">
150 <Button type="submit">
151 <Filter size={14} />
152 Filter
153 </Button>
154 {filtered && (
155 <Link to={base} className="text-sm text-muted hover:text-fg">
156 Clear filters
157 </Link>
158 )}
159 {filters.run && (
160 <span className="font-mono text-xs text-muted">
161 Run {filters.run}
162 </span>
163 )}
164 <span className="grow" />
165 <ButtonLink variant="quiet" to={exportHref("csv")} reloadDocument>
166 <Download size={14} />
167 CSV
168 </ButtonLink>
169 <ButtonLink variant="quiet" to={exportHref("json")} reloadDocument>
170 <Download size={14} />
171 JSON
172 </ButtonLink>
173 </div>
174 </Form>
175
176 <div className="mt-6">
177 {entries.length === 0 ? (
178 <EmptyState title={filtered ? "Nothing matches these filters" : "Nothing recorded yet"}>
179 {filtered
180 ? "Try a wider time range, or clear the filters."
181 : "Entries appear as agents work and as people change things through the API, MCP and git."}
182 </EmptyState>
183 ) : (
184 <AuditTable entries={entries} base={base} />
185 )}
186 </div>
187
188 {(next || filters.before) && (
189 <div className="mt-4 flex gap-4 text-sm">
190 {filters.before && (
191 <Link to={filterHref(base, { ...filters, before: "" })} className="text-muted hover:text-fg">
192 Newest
193 </Link>
194 )}
195 {next && (
196 <Link to={filterHref(base, filters, { before: next })} className="text-muted hover:text-fg">
197 Older
198 </Link>
199 )}
200 </div>
201 )}
202 </div>
203 );
204}