Skip to content

g1t/apps/docs/src/content/docs/guides/audit-log.md

112 lines5,456 bytesCodeBlame
1---
2title: Audit log
3description: Every action agents take with their run credentials, and every change people and tokens make, with whether it was allowed and the rule that decided.
4---
5
6Every workspace keeps an audit log. It records:
7
8- **Everything an agent does** with its [run credentials](/guides/working-with-g1t/#credentials),
9 reads included: every API and MCP call, every clone and fetch, every push.
10- **Every change people and workspace tokens make** through the API, the
11 MCP server and git: opening and closing issues, comments, merges,
12 settings, pushes. Reads by people are not recorded.
13
14- **A repository's lifecycle**, wherever the change was made, g1t.sh
15 included. A transfer is recorded in both workspaces' logs, and a
16 workspace's deletion as `workspace.deleted`, its log's last entry.
17
18| Action | Recorded when |
19| --- | --- |
20| `repo.renamed` | A repository was renamed. |
21| `repo.visibility_changed` | It was made public or private. |
22| `repo.default_branch_changed` | Its default branch changed. |
23| `branch.renamed` | A branch was renamed. |
24| `repo.archived`, `repo.unarchived` | It was archived, or unarchived. |
25| `repo.transferred` | It moved to another workspace. |
26| `repo.deleted`, `repo.restored`, `repo.purged` | It was deleted, restored, or removed for good. |
27| `repo.collaborator_added`, `repo.collaborator_role_changed`, `repo.collaborator_removed` | Someone was given a role on it, had it changed, or lost it. See [access and roles](/guides/access-and-roles/). |
28| `repo.invitation_created`, `repo.invitation_revoked` | Someone was invited to it, or an invitation was withdrawn. |
29| `workspace.base_permission_changed` | An owner changed what members get on every repository. |
30
31Through the API and the MCP server, the call itself is recorded under its
32operation's name too, such as `delete_repo`. See
33[managing a repository](/guides/managing-repositories/).
34
35Refusals are recorded too, with the rule that refused them. Entries are
36only ever added: nothing edits or removes one.
37
38## What an entry says
39
40| Field | What it is |
41| --- | --- |
42| Time | When it happened, to the millisecond. |
43| Actor | Who did it: a person, an agent, or a workspace token. |
44| On behalf of | For an agent, the person it worked for: `g1t on behalf of syntaqx`. |
45| Run | The agent run, with its kind: `implement`, `review`, `update` and so on. |
46| Credential | The id of the token used. |
47| Action | The API or MCP operation, such as `create_issue`, or `git.push` and `git.fetch`. |
48| Target | The repository, the issue or pull request number, and for git the refs it moved. |
49| Outcome | `allowed` or `denied`. |
50| Rule | What decided it: the run's scope, such as `run:implement/tools`; a refusal rule, such as `scope:repository`; or, for people, their own access. A refusal by the repository's own rules is `service` (or `repository` for git). |
51| Result | `ok`, or the reason it failed. |
52| Request id | The request's id, the same one Cloudflare logs it under. |
53
54The rules that refuse an agent are listed under
55[credentials](/guides/working-with-g1t/#credentials).
56
57## Read the log
58
59Open the workspace's settings and choose **Audit log**, or go to
60`g1t.sh/<workspace>/-/audit`.
61
62- **Owners** see everything in the workspace.
63- **Members** see what was done to the workspace's projects, and anything
64 they did, or had done on their behalf. Changes owners made to the
65 workspace itself are for owners.
66
67Filter by actor (a person matches what they did and what agents did for
68them), agent, action, project, outcome, who acted, and a range of days.
69The filters are part of the page's address, so a filtered view can be
70shared with anyone who can see it.
71
72Each agent run's page has a **What it did** section listing its entries in
73order, and a pull request's **Agent** panel shows the latest of what its
74runs did. Both link to the full log, filtered to the run.
75
76## How long it is kept
77
78How far back the log goes depends on the workspace's plan:
79
80| Workspace | Kept |
81| --- | --- |
82| Free | **7 days** |
83| On the [g1t plan](/guides/usage-and-billing/#the-g1t-plan) | **90 days** |
84| Paid for by an [enterprise](/guides/usage-and-billing/#enterprises-and-custom-terms) | **90 days** |
85| Longer, by arrangement | Up to **400 days** |
86
87The log can be read and exported back that far, and no further. Once a
88day, entries older than that are **deleted**, and cannot be brought back:
89export what you need to keep before then. Starting the plan keeps 90 days
90from then on; entries already deleted stay deleted. Ending it goes back to
917 days, and the next daily pass deletes what is older.
92
93For a longer log, such as for a compliance requirement, email
94[support@g1t.sh](mailto:support@g1t.sh). g1t can set the workspace's
95account to keep up to 400 days, and what is set there takes the place of
96the plan's. A [self-hosted](/guides/self-hosting/) g1t that does not charge
97keeps 90 days for every workspace.
98
99## Export
100
101**CSV** and **JSON** on the Audit log page download what the current
102filters match, up to 10,000 entries, newest first. The CSV has one column
103for each field above; a cell that a spreadsheet would read as a formula is
104written as text.
105
106## What is not recorded
107
108- Reads by people and workspace tokens.
109- What people do on the website itself. The API, the MCP server and git
110 are recorded.
111- What g1t does on its own, such as closing a pull request whose agent
112 failed. Those changes are in the pull request's timeline.