Skip to content

Organization audit log

On this page you will learn:

  1. which events go into the organization audit log;
  2. who can open it;
  3. what the log does not contain and where to look for the rest.

The log answers one question: who did what to whose knowledge. Example: Northwind’s security team wants to know who read Ben’s records after he left, and to whom they were opened.

The Audit log tab exists only for the admin and the auditor. Other roles do not see the tab, and the server refuses their requests with org_admin_required.

The auditor role is designed for exactly this kind of oversight: an auditor sees the log but cannot read a single memory record or issue a key.

Event in the accountAPI valueWhenDetails
offboarding startedoffboarding_started“Start offboarding” was clickedRecipient, keys revoked, records by visibility, uploaded sessions
offboarding completedoffboarding_completed“Complete offboarding” was clicked—
handed-over knowledge readread_transferredThe recipient read a leaver’s recordsNumber of records and where: account (account) or agent (mcp)
visibility of a handed-over record changedtransferred_visibility_changedThe recipient opened a leaver’s record to the unit, project or organizationRecord ID, new visibility, node
access_term_changedaccess_term_changedThe admin set, extended or removed an access termNew access end date

Each event has a time, who did it (“Who”) and whose knowledge or access it concerns (“Whose”). The log shows the latest 200 events, newest first.

Sample log after Ben’s departure:

WhenActionWhoWhose
2026-10-12 15:40:02visibility of a handed-over record changedanna@northwind.exampleben@northwind.example
2026-10-12 15:31:47handed-over knowledge readanna@northwind.exampleben@northwind.example
2026-10-12 11:05:10offboarding startedanna@northwind.exampleben@northwind.example
  • Memory content. Only actions, IDs and counts are logged. The rule is built into the function that writes the log: memory text is never passed to it.
  • Ordinary reads and writes. A member searching colleagues’ records or saving new ones does not appear in the organization log; only reads of departed people’s knowledge are tracked.
  • Keys. Neither key secrets nor key hashes are logged.
  • After offboarding, check that the knowledge is read by the person it was handed to, and that the records opened to the team are the right ones.
  • For contractors, the log shows each extension: who extended access and until when.
  • For oversight, give your security reviewer the Auditor role instead of Admin: they see the log but cannot change the structure or read memory.