> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oleander.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit logs

> Every authenticated API request in your organization, with who made it, how they authenticated, and what came back.

The audit log records every authenticated request to the oleander API for your organization, whether it came from the app, an API key, the CLI, an SDK, or an agent over MCP. Use it to answer who did what, when, and with which credential.

Open it at [oleander.dev/app/audit](https://oleander.dev/app/audit).

## What is recorded

Each entry is one request. The table shows the newest entries first and loads older ones as you scroll, and clicking a row opens the full record.

| Field | Description |
| - | - |
| **Time** | When the request was received, shown in your local time zone or UTC (toggle at the top right). The full record always shows UTC. |
| **Principal** | The Human, Application, or Agent that made the request. Hover for the principal ID. |
| **Delegated by** | For a request made with a delegated credential, the principal that delegated it. Former members are shown by ID. |
| **Auth method** | `session` for the app, `jwt` for API keys and other tokens. |
| **Method** and **Endpoint** | The HTTP method and API path. |
| **Status** | The HTTP response status. Failed requests are highlighted, and a request that never returned a response is marked as not recorded. |
| **Source IP** and **User-Agent** | Where the request came from. |

The full record also includes the API key ID for key-based requests, an impersonator ID when a support session acted on the principal's behalf, any error code and message, and the request parameters.

## What is not recorded

Request parameters are filtered to a fixed list of structural fields - identifiers, names, resource and action names, table and namespace names, paging and status fields. SQL text, scripts, chat messages, connection settings, credentials, and uploaded files are never written to the audit log, and a request body over 16 KiB is omitted. Where something was filtered, the record says so instead of showing an empty value.

Reading the audit log is itself an audited request.

## Permissions

Audit logs are an IAM resource with two actions, both on the organization-wide scope **Audit logs → All audit logs**:

| Action | Meaning |
| - | - |
| Describe | View the audit log, including principal identities. Does not require permissions on the resources the entries mention. |
| Manage grants | Delegate audit log access to other roles. Does not itself grant viewing. |

`OrganizationAdmin` holds both, `SecurityAdmin` holds Describe, and `UserAdmin` holds Manage grants. There is no per-entry scope. See [Resources and actions](/iam/resources-and-actions#audit-logs).

<Note>
  The permission definitions ship with the system-managed roles today. Enforcement of **Describe** on the audit page follows once every organization's system-managed roles have been backfilled; until then the page is available to members of the organization.
</Note>
