Skip to content

Learn · Audit & evidence

The workspace audit log

Who changed a role, a key, or a setting inside your work area.

Checked against the product on · written for people who run the account

This is the answer to the audit-log question on a vendor security questionnaire. It is readable by the admins of the work area it covers, and it is append-only.

console.dmzagent.com/settings/audit

Prove

Audit log

1All actorsLast 30 daysExport CSV
2
TimeWhoActionTarget
12:31dana@Role changed to adminsam@
11:02dana@API key createdck_test_…9b17
09:44sam@Rule pack pinnedSupport conduct 1.1.2
3Append-only. Secret material is stripped before an entry is written.
Figure. The audit log, with the actor kept on every row. The workspace audit log: who changed what, when, and against which target.
  1. Open Settings, then Audit log, and set the window.1

  2. Read the rows.2

    Each one names the actor, the action, and what it acted on.

  3. Read the redaction line.3

What lands in the log.
ActionRecorded when
Role changedSomeone is invited, promoted, demoted, or removed.
Key createdAn API key is made.
Key revokedAn API key is revoked.
Setting changedA work-area setting is edited.
Rule pack pinnedA pack is installed, moved to a new version, or removed.
  • The actor email is kept on the row, so the trail stays legible after a person leaves the account.
  • Secret material is stripped before an entry is written, so a key value never reaches the log at all.
  • There is no edit and no delete. Erasing data is a separate flow with its own record.