| 1 | --- |
| 2 | title: Audit log |
| 3 | description: Every action agents take with their run credentials, and every change people and tokens make, with whether it was allowed and the rule that decided. |
| 4 | --- |
| 5 | |
| 6 | Every workspace keeps an audit log. It records: |
| 7 | |
| 8 | - **Everything an agent does** with its [run credentials](/guides/working-with-g1t/#credentials), |
| 9 | reads included: every API and MCP call, every clone and fetch, every push. |
| 10 | - **Every change people and workspace tokens make** through the API, the |
| 11 | MCP server and git: opening and closing issues, comments, merges, |
| 12 | settings, pushes. Reads by people are not recorded. |
| 13 | |
| 14 | - **A repository's lifecycle**, wherever the change was made, g1t.sh |
| 15 | included. A transfer is recorded in both workspaces' logs, and a |
| 16 | workspace's deletion as `workspace.deleted`, its log's last entry. |
| 17 | |
| 18 | | Action | Recorded when | |
| 19 | | --- | --- | |
| 20 | | `repo.renamed` | A repository was renamed. | |
| 21 | | `repo.visibility_changed` | It was made public or private. | |
| 22 | | `repo.default_branch_changed` | Its default branch changed. | |
| 23 | | `branch.renamed` | A branch was renamed. | |
| 24 | | `repo.archived`, `repo.unarchived` | It was archived, or unarchived. | |
| 25 | | `repo.transferred` | It moved to another workspace. | |
| 26 | | `repo.deleted`, `repo.restored`, `repo.purged` | It was deleted, restored, or removed for good. | |
| 27 | | `repo.collaborator_added`, `repo.collaborator_role_changed`, `repo.collaborator_removed` | Someone was given a role on it, had it changed, or lost it. See [access and roles](/guides/access-and-roles/). | |
| 28 | | `repo.invitation_created`, `repo.invitation_revoked` | Someone was invited to it, or an invitation was withdrawn. | |
| 29 | | `workspace.base_permission_changed` | An owner changed what members get on every repository. | |
| 30 | |
| 31 | Through the API and the MCP server, the call itself is recorded under its |
| 32 | operation's name too, such as `delete_repo`. See |
| 33 | [managing a repository](/guides/managing-repositories/). |
| 34 | |
| 35 | Refusals are recorded too, with the rule that refused them. Entries are |
| 36 | only ever added: nothing edits or removes one. |
| 37 | |
| 38 | ## What an entry says |
| 39 | |
| 40 | | Field | What it is | |
| 41 | | --- | --- | |
| 42 | | Time | When it happened, to the millisecond. | |
| 43 | | Actor | Who did it: a person, an agent, or a workspace token. | |
| 44 | | On behalf of | For an agent, the person it worked for: `g1t on behalf of syntaqx`. | |
| 45 | | Run | The agent run, with its kind: `implement`, `review`, `update` and so on. | |
| 46 | | Credential | The id of the token used. | |
| 47 | | Action | The API or MCP operation, such as `create_issue`, or `git.push` and `git.fetch`. | |
| 48 | | Target | The repository, the issue or pull request number, and for git the refs it moved. | |
| 49 | | Outcome | `allowed` or `denied`. | |
| 50 | | Rule | What decided it: the run's scope, such as `run:implement/tools`; a refusal rule, such as `scope:repository`; or, for people, their own access. A refusal by the repository's own rules is `service` (or `repository` for git). | |
| 51 | | Result | `ok`, or the reason it failed. | |
| 52 | | Request id | The request's id, the same one Cloudflare logs it under. | |
| 53 | |
| 54 | The rules that refuse an agent are listed under |
| 55 | [credentials](/guides/working-with-g1t/#credentials). |
| 56 | |
| 57 | ## Read the log |
| 58 | |
| 59 | Open the workspace's settings and choose **Audit log**, or go to |
| 60 | `g1t.sh/<workspace>/-/audit`. |
| 61 | |
| 62 | - **Owners** see everything in the workspace. |
| 63 | - **Members** see what was done to the workspace's projects, and anything |
| 64 | they did, or had done on their behalf. Changes owners made to the |
| 65 | workspace itself are for owners. |
| 66 | |
| 67 | Filter by actor (a person matches what they did and what agents did for |
| 68 | them), agent, action, project, outcome, who acted, and a range of days. |
| 69 | The filters are part of the page's address, so a filtered view can be |
| 70 | shared with anyone who can see it. |
| 71 | |
| 72 | Each agent run's page has a **What it did** section listing its entries in |
| 73 | order, and a pull request's **Agent** panel shows the latest of what its |
| 74 | runs did. Both link to the full log, filtered to the run. |
| 75 | |
| 76 | ## How long it is kept |
| 77 | |
| 78 | How far back the log goes depends on the workspace's plan: |
| 79 | |
| 80 | | Workspace | Kept | |
| 81 | | --- | --- | |
| 82 | | Free | **7 days** | |
| 83 | | On the [g1t plan](/guides/usage-and-billing/#the-g1t-plan) | **90 days** | |
| 84 | | Paid for by an [enterprise](/guides/usage-and-billing/#enterprises-and-custom-terms) | **90 days** | |
| 85 | | Longer, by arrangement | Up to **400 days** | |
| 86 | |
| 87 | The log can be read and exported back that far, and no further. Once a |
| 88 | day, entries older than that are **deleted**, and cannot be brought back: |
| 89 | export what you need to keep before then. Starting the plan keeps 90 days |
| 90 | from then on; entries already deleted stay deleted. Ending it goes back to |
| 91 | 7 days, and the next daily pass deletes what is older. |
| 92 | |
| 93 | For a longer log, such as for a compliance requirement, email |
| 94 | [support@g1t.sh](mailto:support@g1t.sh). g1t can set the workspace's |
| 95 | account to keep up to 400 days, and what is set there takes the place of |
| 96 | the plan's. A [self-hosted](/guides/self-hosting/) g1t that does not charge |
| 97 | keeps 90 days for every workspace. |
| 98 | |
| 99 | ## Export |
| 100 | |
| 101 | **CSV** and **JSON** on the Audit log page download what the current |
| 102 | filters match, up to 10,000 entries, newest first. The CSV has one column |
| 103 | for each field above; a cell that a spreadsheet would read as a formula is |
| 104 | written as text. |
| 105 | |
| 106 | ## What is not recorded |
| 107 | |
| 108 | - Reads by people and workspace tokens. |
| 109 | - What people do on the website itself. The API, the MCP server and git |
| 110 | are recorded. |
| 111 | - What g1t does on its own, such as closing a pull request whose agent |
| 112 | failed. Those changes are in the pull request's timeline. |