> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.governanceaicore.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.governanceaicore.com/_mcp/server.

# Audit & Activity Logs

> Complete audit trail and activity logging for compliance and security

# Audit & Activity Logs

GovernanceAI maintains a complete, immutable audit trail of all system activities for compliance, security monitoring, and investigation.

## What Gets Logged?

Every action in GovernanceAI generates an audit log entry:

### User Actions

* Login/logout
* API key creation/rotation/revocation
* Policy changes
* Guardrail modifications
* Settings updates
* Data exports
* Report generation

### API Calls

* Guardrail evaluations
* Policy enforcement decisions
* Scan requests
* Red-team campaigns
* Report generation

### System Events

* Deployment changes
* Integration connections/disconnections
* Database operations
* Error events
* Security incidents

### Data Access

* Who accessed what data
* When it was accessed
* What operation was performed
* From which IP/client

## Log Entry Structure

Each audit log includes:

```json
{
  "log_id": "log_1234567890",
  "timestamp": "2024-01-15T10:30:45.123Z",
  "organization_id": "org_123",
  "workspace_id": "ws_456",
  "actor": {
    "type": "user",
    "id": "user_789",
    "email": "admin@company.com",
    "ip_address": "192.168.1.1",
    "user_agent": "Mozilla/5.0..."
  },
  "resource": {
    "type": "policy",
    "id": "policy_abc",
    "name": "Production Governance"
  },
  "action": "policy_updated",
  "severity": "medium",
  "status": "success",
  "changes": {
    "before": {"version": "1.0"},
    "after": {"version": "2.0"}
  },
  "details": {
    "change_description": "Added jailbreak detection guardrail",
    "reason": "Security hardening after red-team findings"
  }
}
```

## Querying Audit Logs

### Via Dashboard

* Go to **Settings** → **Audit Log**
* Filter by:
  * Date range
  * Action type
  * User/actor
  * Resource type
  * Status (success/failure)
* View details or export

### Via API

```bash
# Get all audit logs
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/audit/logs

# Filter by date
curl -H "Authorization: Bearer $API_KEY" \
  'https://api.governanceai.com/v1/audit/logs?start_date=2024-01-01&end_date=2024-01-31'

# Filter by action
curl -H "Authorization: Bearer $API_KEY" \
  'https://api.governanceai.com/v1/audit/logs?action=guardrail_updated'

# Filter by user
curl -H "Authorization: Bearer $API_KEY" \
  'https://api.governanceai.com/v1/audit/logs?actor_id=user_123'

# Combine filters
curl -H "Authorization: Bearer $API_KEY" \
  'https://api.governanceai.com/v1/audit/logs?action=policy_updated&severity=high&status=success'
```

### Pagination

```bash
# Get page 1, 100 results per page
curl -H "Authorization: Bearer $API_KEY" \
  'https://api.governanceai.com/v1/audit/logs?page=1&page_size=100'

# Response
{
  "entries": [...],
  "pagination": {
    "page": 1,
    "page_size": 100,
    "total_count": 5432,
    "total_pages": 55
  }
}
```

## Activity Log Retention

### Retention Policies

| Plan           | Retention | Searchable | Archival               |
| -------------- | --------- | ---------- | ---------------------- |
| **Pro**        | 90 days   | 30 days    | 1 year (cold storage)  |
| **Enterprise** | 1 year    | 1 year     | 3 years (cold storage) |
| **Compliance** | 3 years   | 3 years    | 7 years (cold storage) |

### Archival & Export

```bash
# Export logs for archival
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/audit/logs/export \
  -d '{
    "format": "json",
    "start_date": "2023-01-01",
    "end_date": "2023-12-31"
  }' \
  --output audit_logs_2023.json.gz

# Archive to long-term storage
curl -X POST \
  -H "Authorization: Bearer $API_KEY" \
  -F "file=@audit_logs_2023.json.gz" \
  https://api.governanceai.com/v1/audit/archive
```

## Security & Integrity

### Immutable Logs

Once written, logs cannot be modified:

* ❌ Cannot edit existing entries
* ❌ Cannot delete entries
* ✅ Can only query/export
* ✅ Hash chain prevents tampering

### Hash Verification

Each entry includes a cryptographic hash of the previous entry:

```
Entry N:
├─ log_id: log_n
├─ data: {...}
├─ hash: sha256(entry_n_data)
├─ previous_hash: sha256(entry_n-1_data)
```

This creates a tamper-evident chain. Any modification would break the hash chain.

### Access Control

Who can view audit logs:

* **Organization Admin** - All logs for organization
* **Workspace Admin** - Logs for their workspace only
* **Security/Compliance** - Logs relevant to their function
* **Regular Users** - Their own action logs only
* **Auditors** - Read-only access to all logs

```bash
# Configure access
curl -X POST https://api.governanceai.com/v1/rbac/roles/edit \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "role": "auditor",
    "permissions": {
      "audit": ["read"],
      "compliance": ["read"]
    }
  }'
```

## SIEM Integration

Export logs to your Security Information and Event Management system:

### Syslog Integration

```bash
# Configure syslog forwarding
curl -X POST https://api.governanceai.com/v1/integrations/syslog \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "enabled": true,
    "syslog_host": "siem.company.com",
    "syslog_port": 514,
    "protocol": "tcp",
    "facility": "local0",
    "format": "RFC3164"
  }'
```

### CloudWatch Integration

```bash
# Forward to AWS CloudWatch
curl -X POST https://api.governanceai.com/v1/integrations/cloudwatch \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "enabled": true,
    "log_group": "/governanceai/audit",
    "aws_region": "us-east-1",
    "aws_access_key_id": "***",
    "aws_secret_access_key": "***"
  }'
```

### Splunk Integration

```bash
# Forward to Splunk
curl -X POST https://api.governanceai.com/v1/integrations/splunk \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "enabled": true,
    "hec_token": "***",
    "hec_endpoint": "https://splunk.company.com:8088",
    "sourcetype": "_json"
  }'
```

## Alerts & Notifications

### Real-Time Alerts

Get notified of critical events:

```bash
# Alert on suspicious activity
curl -X POST https://api.governanceai.com/v1/alerts/rules \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "name": "Unauthorized API Key Creation",
    "condition": {
      "action": "api_key_created",
      "actor_role": "not:admin"
    },
    "severity": "critical",
    "notification_channels": ["email", "slack"],
    "recipients": ["security@company.com"]
  }'

# Alert on bulk data export
curl -X POST https://api.governanceai.com/v1/alerts/rules \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "name": "Large Data Export",
    "condition": {
      "action": "logs_exported",
      "entry_count_greater_than": 10000
    },
    "notification_channels": ["slack"],
    "recipients": ["security-team"]
  }'
```

## Reports & Analysis

### Audit Summary Report

```bash
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/audit/reports/summary \
  -d '{
    "period": "monthly",
    "start_date": "2024-01-01",
    "end_date": "2024-01-31"
  }'

# Returns:
{
  "period": "January 2024",
  "total_events": 52430,
  "by_action": {
    "guardrail_evaluated": 50000,
    "policy_updated": 150,
    "user_login": 250,
    "api_key_created": 20,
    "scan_executed": 10
  },
  "by_severity": {
    "critical": 2,
    "high": 45,
    "medium": 380,
    "low": 52003
  },
  "failed_actions": 12,
  "failed_percentage": 0.02
}
```

### User Activity Report

```bash
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/audit/reports/user-activity \
  -d '{"user_id": "user_123", "period": "2024-01"}'

# Returns activity summary for specific user
```

## Compliance Use Cases

### SOC2 Audit Trail

GovernanceAI's audit logs provide evidence for SOC2 CC7.2 (Monitoring):

```
Control: CC7.2 - System Monitoring

Evidence:
├─ Audit logs enabled: ✅
├─ Retention period: 1 year ✅
├─ Immutable logs: ✅
├─ Access controls: ✅
└─ Regular review: ✅
```

### HIPAA Audit Controls

Maps to HIPAA 45 CFR § 164.312(b) - Audit Controls:

```
Requirement: Log all accesses to ePHI
GovernanceAI Provides:
├─ User authentication logs
├─ Data access logs
├─ Change logs (policy/guardrail updates)
├─ Error and security event logs
└─ Immutable audit trail
```

### GDPR Right to Audit

Provides evidence for GDPR Article 32 (Security):

```
Requirement: Demonstrate appropriate security measures
Evidence:
├─ User access logs
├─ Data processing logs
├─ Encryption status
├─ Incident response logs
└─ Regular security reviews
```

## Best Practices

✅ **Do:**

* Review audit logs regularly
* Set up alerts for critical events
* Export logs regularly for backup
* Archive old logs for compliance
* Monitor for suspicious patterns
* Integrate with SIEM
* Test log integrity periodically

❌ **Don't:**

* Ignore audit logs
* Delete or modify logs
* Store logs without backup
* Disable audit logging
* Share logs without access control
* Forget to review sensitive actions

## Next Steps

* **[Compliance Frameworks](./04-compliance-frameworks.mdx)** - Map logs to compliance
* **[Running Scans](/usage-guides/scans)** - Monitor scan activity
* **[API Reference](/api)** - Audit API endpoints