Skip to main content
The Admin Log captures security-relevant events across your organization. It provides an audit trail for compliance and incident investigation.
The Admin Log is restricted to users with Admin or Owner roles. See Roles & Permissions for details.

Events Tracked

The Admin Log captures the following events. Coverage is still expanding, and the gaps called out below are tracked for remediation; where an event is not yet recorded, treat your identity provider’s logs as the authoritative record.

Member Management

  • Member invited to organization
  • Member accepted invitation
  • Member invitation revoked
  • Member removed from organization
  • Member role changed (team-scoped only)
Changing a member’s organization role is not recorded today, including a promotion to Admin. Team-scoped role changes are. Use your identity provider’s logs for organization-level role changes.

Authentication

  • SSO login
  • SSO login failure
  • SSO configuration enabled or disabled
Email-code (magic link) sign-in and account lockout are not recorded today. Use your identity provider’s logs for those.

Organization & Structure

  • Governance posture changed
  • Default provisioned role changed
  • Drift enforcement changed
  • Workspace updated
Organization rename, slug and allowed-domain changes, organization create and delete, workspace create and delete, and all team create, update, and delete actions are not recorded today.

Device Lifecycle

Device register, link, unlink, archive, and delete are not recorded today.

Guardrail Configuration

  • Guardrail created (custom guardrails)
  • Guardrail updated (enforcement mode or configuration changed)
  • Guardrail deleted (custom guardrails)
  • Guardrail enabled
  • Guardrail disabled
Creating, deleting, or disabling a security control is logged at warning severity to ensure visibility when protection is removed. Enabling or updating a guardrail is logged at info severity. Each guardrail event includes metadata describing what changed:

Event Details

Each event in the Admin Log records:

Identity attribution

Audit and trace entries in the Hub dashboard surface the user behind each event with three visual cues. The full attribution model is documented on the Identities page.
  • Assurance dot — a small coloured dot next to the user’s name indicates how the event was attributed.
    • Green (authenticated) — performed by a logged-in user with an active session.
    • Amber (gateway, shown as Device-attributed): attributed via the device’s registered owner rather than a session. Typical for unauthenticated stdio traffic on a personal device.
    • Grey — no identity could be attributed.
  • Role chip — shows the user’s organization role (owner, admin, member, or viewer) when known.
  • Non-member badge — appears when an event is attributed to a user who is not a current member of the organization. Use this to spot activity from offboarded employees or external identities that were never granted membership.
Clicking the user’s name in any drawer opens their identity detail page, which shows aggregate activity, peak hours, and any anomaly findings for that identity.

Viewing the Admin Log

The Admin Log is accessible from the Hub web interface:
  1. Navigate to your organization in Hub
  2. Select Admin Log from the sidebar
  3. Browse events chronologically (newest first)
Events can be filtered by action type, actor, target, and time range.