Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 1 | import { Download, Filter } from "lucide-react"; |
| 2 | import { Form, Link, data } from "react-router"; | |
| 3 | ||
| 4 | import type { Route } from "./+types/audit"; | |
| 5 | import { page } from "../../lib/meta"; | |
| 6 | import { AuditTable } from "../../components/audit"; | |
| 7 | import { Button, ButtonLink, EmptyState, Field, Input } from "../../components/ui"; | |
| Chat controls, public profiles, shadcn selects, and no Docs tab in a project | 8 | import { SelectField } from "../../components/ui/select"; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 9 | import { type AuditFilters, filterHref, parseFilters, toQuery } from "../../lib/audit"; |
| Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put | 10 | import { auditPage, auditRetention } from "../../lib/audit.server"; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 11 | import { repos } from "../../lib/services.server"; |
| 12 | import { requireUser, roleIn } from "../../lib/session.server"; | |
| 13 | ||
| 14 | const PAGE_SIZE = 100; | |
| 15 | ||
| 16 | /** Actions worth offering in the filter; any other can be typed. */ | |
| 17 | const COMMON_ACTIONS = [ | |
| 18 | "git.push", | |
| 19 | "git.fetch", | |
| 20 | "create_issue", | |
| 21 | "add_comment", | |
| 22 | "record_session", | |
| 23 | "mark_pull_request_ready", | |
| 24 | "review_pull_request", | |
| 25 | "merge_pull_request", | |
| 26 | "remember", | |
| 27 | "message_agent", | |
| 28 | ]; | |
| 29 | ||
| 30 | export function meta({ params, ...args }: Route.MetaArgs) { | |
| 31 | return page(args, { title: `Audit log · ${params.owner} · g1t` }); | |
| 32 | } | |
| 33 | ||
| 34 | export async function loader({ params, context, request }: Route.LoaderArgs) { | |
| 35 | const viewer = requireUser(context, request); | |
| 36 | const workspace = params.owner.toLowerCase(); | |
| 37 | const role = roleIn(viewer, workspace); | |
| 38 | if (!role) throw data("Only members of this workspace can read its audit log.", { status: 404 }); | |
| 39 | const filters = parseFilters(new URL(request.url).searchParams); | |
| 40 | const { visibility: _, ...query } = toQuery(workspace, { kind: "all" }, filters, PAGE_SIZE); | |
| Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put | 41 | const [found, projects, retention] = await Promise.all([ |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 42 | auditPage(viewer, query), |
| 43 | repos.list(viewer, { namespace: workspace }).catch(() => []), | |
| Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put | 44 | auditRetention(workspace), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 45 | ]); |
| 46 | return { | |
| 47 | workspace, | |
| 48 | role, | |
| 49 | filters, | |
| 50 | entries: found?.entries ?? [], | |
| 51 | next: found?.next ?? null, | |
| 52 | projects: projects.map((repo) => repo.name), | |
| Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put | 53 | retention, |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 54 | }; |
| 55 | } | |
| 56 | ||
| 57 | function FilterField({ | |
| 58 | label, | |
| 59 | name, | |
| 60 | value, | |
| 61 | placeholder, | |
| 62 | list, | |
| 63 | }: { | |
| 64 | label: string; | |
| 65 | name: keyof AuditFilters; | |
| 66 | value: string; | |
| 67 | placeholder?: string; | |
| 68 | list?: string; | |
| 69 | }) { | |
| 70 | return ( | |
| 71 | <Field label={label}> | |
| 72 | <Input name={name} defaultValue={value} placeholder={placeholder} list={list} /> | |
| 73 | </Field> | |
| 74 | ); | |
| 75 | } | |
| 76 | ||
| Chat controls, public profiles, shadcn selects, and no Docs tab in a project | 77 | /** As tall as the inputs beside it. */ |
| 78 | const SELECT = "h-auto py-2"; | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 79 | |
| 80 | export default function WorkspaceAudit({ loaderData }: Route.ComponentProps) { | |
| Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put | 81 | const { workspace, role, filters, entries, next, projects, retention } = loaderData; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 82 | const base = `/${workspace}/-/audit`; |
| 83 | const filtered = Object.entries(filters).some(([key, value]) => key !== "before" && value); | |
| 84 | const exportHref = (format: "csv" | "json") => filterHref(`${base}/export`, { ...filters, before: "" }) + `${filtered ? "&" : "?"}format=${format}`; | |
| 85 | return ( | |
| 86 | <div> | |
| 87 | <p className="max-w-3xl text-sm text-muted"> | |
| 88 | Every action taken with an agent run's credentials, reads included, and every change people and | |
| 89 | workspace tokens make through the API, MCP and git: who did it, on whose behalf, with which | |
| 90 | credential, to what, and whether it was allowed. Refusals name the rule that refused them. | |
| 91 | {role === "owner" | |
| 92 | ? " As an owner you see the whole workspace." | |
| 93 | : " As a member you see what was done to the workspace's projects, and what was done by you or on your behalf."} | |
| Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put | 94 | {retention != null && |
| Audit logs are kept by plan: a week on free, 90 days on the plan, and what staff set for an account in sudo | 95 | ` The log goes back ${retention} days, and exports the same; older entries are deleted each day.`} |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 96 | </p> |
| 97 | ||
| 98 | <Form method="get" className="mt-6 rounded-xl border border-line bg-surface p-4"> | |
| 99 | <div className="grid gap-4 sm:grid-cols-2 lg:grid-cols-4"> | |
| 100 | <FilterField label="Actor" name="actor" value={filters.actor} placeholder="A person, or whom an agent worked for" /> | |
| g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent | 101 | <FilterField label="Agent" name="agent" value={filters.agent} placeholder="g1t" /> |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 102 | <FilterField label="Action" name="action" value={filters.action} placeholder="git.push" list="audit-actions" /> |
| 103 | <FilterField label="Project" name="project" value={filters.project} placeholder="Any" list="audit-projects" /> | |
| 104 | <Field label="Outcome"> | |
| Chat controls, public profiles, shadcn selects, and no Docs tab in a project | 105 | <SelectField |
| 106 | key={`outcome-${filters.outcome}`} | |
| 107 | name="outcome" | |
| 108 | defaultValue={filters.outcome} | |
| 109 | className={SELECT} | |
| 110 | options={[ | |
| 111 | { value: "", label: "Any" }, | |
| 112 | { value: "allowed", label: "Allowed" }, | |
| 113 | { value: "denied", label: "Denied" }, | |
| 114 | ]} | |
| 115 | /> | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 116 | </Field> |
| 117 | <Field label="Who"> | |
| Chat controls, public profiles, shadcn selects, and no Docs tab in a project | 118 | <SelectField |
| 119 | key={`kind-${filters.kind}`} | |
| 120 | name="kind" | |
| 121 | defaultValue={filters.kind} | |
| 122 | className={SELECT} | |
| 123 | options={[ | |
| 124 | { value: "", label: "Anyone" }, | |
| 125 | { value: "agent", label: "Agents" }, | |
| 126 | { value: "person", label: "People" }, | |
| 127 | { value: "workspace", label: "Workspace tokens" }, | |
| 128 | ]} | |
| 129 | /> | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 130 | </Field> |
| 131 | <Field label="From"> | |
| 132 | <Input type="date" name="from" defaultValue={filters.from} /> | |
| 133 | </Field> | |
| 134 | <Field label="To"> | |
| 135 | <Input type="date" name="to" defaultValue={filters.to} /> | |
| 136 | </Field> | |
| 137 | </div> | |
| 138 | {filters.run && <input type="hidden" name="run" value={filters.run} />} | |
| 139 | <datalist id="audit-actions"> | |
| 140 | {COMMON_ACTIONS.map((action) => ( | |
| 141 | <option key={action} value={action} /> | |
| 142 | ))} | |
| 143 | </datalist> | |
| 144 | <datalist id="audit-projects"> | |
| 145 | {projects.map((name) => ( | |
| 146 | <option key={name} value={name} /> | |
| 147 | ))} | |
| 148 | </datalist> | |
| 149 | <div className="mt-4 flex flex-wrap items-center gap-3"> | |
| 150 | <Button type="submit"> | |
| 151 | <Filter size={14} /> | |
| 152 | Filter | |
| 153 | </Button> | |
| 154 | {filtered && ( | |
| 155 | <Link to={base} className="text-sm text-muted hover:text-fg"> | |
| 156 | Clear filters | |
| 157 | </Link> | |
| 158 | )} | |
| 159 | {filters.run && ( | |
| 160 | <span className="font-mono text-xs text-muted"> | |
| 161 | Run {filters.run} | |
| 162 | </span> | |
| 163 | )} | |
| 164 | <span className="grow" /> | |
| 165 | <ButtonLink variant="quiet" to={exportHref("csv")} reloadDocument> | |
| 166 | <Download size={14} /> | |
| 167 | CSV | |
| 168 | </ButtonLink> | |
| 169 | <ButtonLink variant="quiet" to={exportHref("json")} reloadDocument> | |
| 170 | <Download size={14} /> | |
| 171 | JSON | |
| 172 | </ButtonLink> | |
| 173 | </div> | |
| 174 | </Form> | |
| 175 | ||
| 176 | <div className="mt-6"> | |
| 177 | {entries.length === 0 ? ( | |
| 178 | <EmptyState title={filtered ? "Nothing matches these filters" : "Nothing recorded yet"}> | |
| 179 | {filtered | |
| 180 | ? "Try a wider time range, or clear the filters." | |
| 181 | : "Entries appear as agents work and as people change things through the API, MCP and git."} | |
| 182 | </EmptyState> | |
| 183 | ) : ( | |
| 184 | <AuditTable entries={entries} base={base} /> | |
| 185 | )} | |
| 186 | </div> | |
| 187 | ||
| 188 | {(next || filters.before) && ( | |
| 189 | <div className="mt-4 flex gap-4 text-sm"> | |
| 190 | {filters.before && ( | |
| 191 | <Link to={filterHref(base, { ...filters, before: "" })} className="text-muted hover:text-fg"> | |
| 192 | Newest | |
| 193 | </Link> | |
| 194 | )} | |
| 195 | {next && ( | |
| 196 | <Link to={filterHref(base, filters, { before: next })} className="text-muted hover:text-fg"> | |
| 197 | Older | |
| 198 | </Link> | |
| 199 | )} | |
| 200 | </div> | |
| 201 | )} | |
| 202 | </div> | |
| 203 | ); | |
| 204 | } |