Audit

Space history, tenant events and chain verification.

Raw Markdown for agents: audit.md. MCP: read_guide("audit").

The audit log records every operation with actor, channel, request and result. Tenant events are signed and chained, so history cannot be changed afterwards.

Operations:

  • audit.space_events.list and audit.space_events.get: what happened in one Space. Every member can list; request, snapshots and result are only shown to Space managers and tenant admins (others get details_hidden).
  • audit.events.list, audit.events.get, audit.change_sets.get, audit.api_requests.list and audit.chain.verify: tenant-wide history, request metadata and signature checks. Admin only.

Rules:

  • All audit operations are read-only; nothing in the log can be edited.
  • Use the Space events to explain to a user who changed what; use the tenant operations only with an admin key and the audit:read scope.