Docs

Console: audit log

Hash-chained record of configuration changes across the organization — who did what, and when.

Every configuration action taken in the console (publishing a statement, rotating or revoking a key, approving a DSAR, inviting someone, changing a role…) is recorded here: actor, action, target and timestamp.

The audit log covers configuration changes, not consent events. Subject consent lives in the vault — that’s where to look for who granted or withdrew consent, and when.

Chain verification

Each entry embeds a hash computed from its own content plus the previous entry’s hash — a hash chain. Tampering with or deleting a middle entry breaks the chain from that point on, making the log tamper-evident, not just read-only.

Also available via GET /admin/organizations/:id/audit-log with an sk_ key, to feed your own SIEM or export it.