[{"data":1,"prerenderedAt":1294},["ShallowReactive",2],{"navigation_docs_en":3,"-en-concepts-audit-logs":270,"-en-concepts-audit-logs-surround":1289},[4,30,68,98,182,260],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":6},"Getting Started",false,"\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,15,20,25],{"title":11,"path":12,"stem":13,"icon":14},"Introduction","\u002Fen\u002Fgetting-started\u002Fintroduction","en\u002F1.getting-started\u002F2.introduction","i-lucide-house",{"title":16,"path":17,"stem":18,"icon":19},"Quickstart","\u002Fen\u002Fgetting-started\u002Finstallation","en\u002F1.getting-started\u002F3.installation","i-lucide-download",{"title":21,"path":22,"stem":23,"icon":24},"Use Cases","\u002Fen\u002Fgetting-started\u002Fuse-cases","en\u002F1.getting-started\u002F4.use-cases","i-lucide-layers",{"title":26,"path":27,"stem":28,"icon":29},"Concepts","\u002Fen\u002Fgetting-started\u002Fconcepts","en\u002F1.getting-started\u002F5.concepts","i-lucide-book",{"title":26,"path":31,"stem":32,"children":33,"page":6},"\u002Fen\u002Fconcepts","en\u002F2.concepts",[34,38,43,48,53,58,63],{"title":35,"path":36,"stem":37,"icon":14},"Organization","\u002Fen\u002Fconcepts\u002Forganization","en\u002F2.concepts\u002F1.organization",{"title":39,"path":40,"stem":41,"icon":42},"Data Model","\u002Fen\u002Fconcepts\u002Fdata-model","en\u002F2.concepts\u002F2.data-model","i-lucide-database",{"title":44,"path":45,"stem":46,"icon":47},"Access Control","\u002Fen\u002Fconcepts\u002Faccess-permissions","en\u002F2.concepts\u002F3.access-permissions","i-lucide-user-key",{"title":49,"path":50,"stem":51,"icon":52},"Audit Logs","\u002Fen\u002Fconcepts\u002Faudit-logs","en\u002F2.concepts\u002F4.audit-logs","i-lucide-scroll-text",{"title":54,"path":55,"stem":56,"icon":57},"Introspection","\u002Fen\u002Fconcepts\u002Fintrospection","en\u002F2.concepts\u002F6.introspection","i-lucide-database-search",{"title":59,"path":60,"stem":61,"icon":62},"Query Engine","\u002Fen\u002Fconcepts\u002Fquery-engine","en\u002F2.concepts\u002F7.query-engine","i-lucide-workflow",{"title":64,"path":65,"stem":66,"icon":67},"AI","\u002Fen\u002Fconcepts\u002Fai","en\u002F2.concepts\u002F8.ai","i-lucide-sparkles",{"title":69,"path":70,"stem":71,"children":72,"page":6},"Guides","\u002Fen\u002Fguides","en\u002F4.guides",[73,78,83,88,93],{"title":74,"path":75,"stem":76,"icon":77},"REST API Quickstart","\u002Fen\u002Fguides\u002Frest-api","en\u002F4.guides\u002F1.rest-api","i-lucide-plug",{"title":79,"path":80,"stem":81,"icon":82},"SDK Quickstart","\u002Fen\u002Fguides\u002Fsdk","en\u002F4.guides\u002F2.sdk","i-lucide-terminal",{"title":84,"path":85,"stem":86,"icon":87},"Configure SSO","\u002Fen\u002Fguides\u002Fconfigure-sso","en\u002F4.guides\u002F3.configure-sso","i-lucide-key-round",{"title":89,"path":90,"stem":91,"icon":92},"Configure MCP","\u002Fen\u002Fguides\u002Fmcp","en\u002F4.guides\u002F4.mcp","i-lucide-brain-cog",{"title":94,"path":95,"stem":96,"icon":97},"Customize Content Space","\u002Fen\u002Fguides\u002Fcustomize-content-space","en\u002F4.guides\u002F5.customize-content-space","i-lucide-columns-3-cog",{"title":99,"path":100,"stem":101,"children":102,"page":6},"Developer","\u002Fen\u002Fdeveloper","en\u002F5.developer",[103,158],{"title":104,"path":105,"stem":106,"children":107,"page":6},"Data Access","\u002Fen\u002Fdeveloper\u002Fapi","en\u002F5.developer\u002F1.api",[108,113,118,123,128,133,138,143,148,153],{"title":109,"path":110,"stem":111,"icon":112},"Overview","\u002Fen\u002Fdeveloper\u002Fapi\u002Foverview","en\u002F5.developer\u002F1.api\u002F1.overview","i-lucide-globe",{"title":114,"path":115,"stem":116,"icon":117},"Errors","\u002Fen\u002Fdeveloper\u002Fapi\u002Ferrors","en\u002F5.developer\u002F1.api\u002F10.errors","i-lucide-alert-triangle",{"title":119,"path":120,"stem":121,"icon":122},"Authentication","\u002Fen\u002Fdeveloper\u002Fapi\u002Fauthentication","en\u002F5.developer\u002F1.api\u002F2.authentication","i-lucide-lock",{"title":124,"path":125,"stem":126,"icon":127},"Reading Data","\u002Fen\u002Fdeveloper\u002Fapi\u002Freading-data","en\u002F5.developer\u002F1.api\u002F3.reading-data","i-lucide-book-open",{"title":129,"path":130,"stem":131,"icon":132},"Writing Data","\u002Fen\u002Fdeveloper\u002Fapi\u002Fwriting-data","en\u002F5.developer\u002F1.api\u002F4.writing-data","i-lucide-pencil",{"title":134,"path":135,"stem":136,"icon":137},"Filtering","\u002Fen\u002Fdeveloper\u002Fapi\u002Ffiltering","en\u002F5.developer\u002F1.api\u002F5.filtering","i-lucide-filter",{"title":139,"path":140,"stem":141,"icon":142},"Field Selection","\u002Fen\u002Fdeveloper\u002Fapi\u002Ffield-selection","en\u002F5.developer\u002F1.api\u002F6.field-selection","i-lucide-list-checks",{"title":144,"path":145,"stem":146,"icon":147},"Sorting & Pagination","\u002Fen\u002Fdeveloper\u002Fapi\u002Fsorting-pagination","en\u002F5.developer\u002F1.api\u002F7.sorting-pagination","i-lucide-arrow-up-down",{"title":149,"path":150,"stem":151,"icon":152},"Relational Data","\u002Fen\u002Fdeveloper\u002Fapi\u002Frelational-data","en\u002F5.developer\u002F1.api\u002F8.relational-data","i-lucide-network",{"title":154,"path":155,"stem":156,"icon":157},"Files & Assets","\u002Fen\u002Fdeveloper\u002Fapi\u002Ffiles","en\u002F5.developer\u002F1.api\u002F9.files","i-lucide-file-up",{"title":159,"path":160,"stem":161,"children":162,"page":6},"Client SDK","\u002Fen\u002Fdeveloper\u002Fsdk","en\u002F5.developer\u002F2.sdk",[163,167,172,177],{"title":164,"path":165,"stem":166,"icon":19},"Installation","\u002Fen\u002Fdeveloper\u002Fsdk\u002Finstallation","en\u002F5.developer\u002F2.sdk\u002F1.installation",{"title":168,"path":169,"stem":170,"icon":171},"Client Setup","\u002Fen\u002Fdeveloper\u002Fsdk\u002Fclient-setup","en\u002F5.developer\u002F2.sdk\u002F2.client-setup","i-lucide-settings",{"title":173,"path":174,"stem":175,"icon":176},"Type System","\u002Fen\u002Fdeveloper\u002Fsdk\u002Ftype-system","en\u002F5.developer\u002F2.sdk\u002F3.type-system","i-lucide-braces",{"title":178,"path":179,"stem":180,"icon":181},"Advanced","\u002Fen\u002Fdeveloper\u002Fsdk\u002Fadvanced","en\u002F5.developer\u002F2.sdk\u002F5.advanced","i-lucide-puzzle",{"title":183,"path":184,"stem":185,"children":186,"page":6},"Reference","\u002Fen\u002Freference","en\u002F6.reference",[187,191,207,211,216,231],{"title":188,"path":189,"stem":190,"icon":171},"Configuration","\u002Fen\u002Freference\u002Fenvironment-variables","en\u002F6.reference\u002F1.environment-variables",{"title":192,"path":193,"stem":194,"children":195,"icon":77},"Connectors","\u002Fen\u002Freference\u002Fconnectors","en\u002F6.reference\u002F2.connectors\u002Findex",[196,197,202],{"title":192,"path":193,"stem":194,"icon":77},{"title":198,"path":199,"stem":200,"icon":201},"PostgreSQL and Supabase","\u002Fen\u002Freference\u002Fconnectors\u002Fpostgresql-supabase","en\u002F6.reference\u002F2.connectors\u002F1.postgresql-supabase","i-simple-icons-postgresql",{"title":203,"path":204,"stem":205,"icon":206},"MySQL and MariaDB","\u002Fen\u002Freference\u002Fconnectors\u002Fmysql-mariadb","en\u002F6.reference\u002F2.connectors\u002F2.mysql-mariadb","i-simple-icons-mysql",{"title":208,"path":209,"stem":210,"icon":176},"Data Types Representation","\u002Fen\u002Freference\u002Fdata-types","en\u002F6.reference\u002F3.data-types",{"title":212,"path":213,"stem":214,"icon":215},"Permissions Reference","\u002Fen\u002Freference\u002Fpermissions","en\u002F6.reference\u002F4.permissions","i-lucide-shield",{"title":217,"path":218,"stem":219,"children":220,"page":6},"API Reference","\u002Fen\u002Freference\u002Fapi-reference","en\u002F6.reference\u002F5.api-reference",[221,226],{"title":222,"path":223,"stem":224,"icon":225},"System Endpoints","\u002Fen\u002Freference\u002Fapi-reference\u002Fsystem-endpoints","en\u002F6.reference\u002F5.api-reference\u002F1.system-endpoints","i-lucide-server",{"title":227,"path":228,"stem":229,"icon":230},"OpenAPI Spec","\u002Fen\u002Freference\u002Fapi-reference\u002Fopenapi-spec","en\u002F6.reference\u002F5.api-reference\u002F2.openapi-spec","i-lucide-file-code",{"title":232,"path":233,"stem":234,"children":235,"page":6},"Pitfalls","\u002Fen\u002Freference\u002Fpitfalls","en\u002F6.reference\u002F6.pitfalls",[236,240,245,250,255],{"title":109,"path":237,"stem":238,"icon":239},"\u002Fen\u002Freference\u002Fpitfalls\u002Foverview","en\u002F6.reference\u002F6.pitfalls\u002F1.overview","i-lucide-triangle-alert",{"title":241,"path":242,"stem":243,"icon":244},"Concurrent Migrations","\u002Fen\u002Freference\u002Fpitfalls\u002Fconcurrent-migrations","en\u002F6.reference\u002F6.pitfalls\u002F2.concurrent-migrations","i-lucide-git-merge",{"title":246,"path":247,"stem":248,"icon":249},"Instance Configuration","\u002Fen\u002Freference\u002Fpitfalls\u002Finstance-configuration-related-problems","en\u002F6.reference\u002F6.pitfalls\u002F3.instance-configuration-related-problems","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Overly Permissive Public Roles","\u002Fen\u002Freference\u002Fpitfalls\u002Foverly-permissive","en\u002F6.reference\u002F6.pitfalls\u002F4.overly-permissive","i-lucide-shield-off",{"title":256,"path":257,"stem":258,"icon":259},"No Aggregates","\u002Fen\u002Freference\u002Fpitfalls\u002Fno-aggregates","en\u002F6.reference\u002F6.pitfalls\u002F5.no-aggregates","i-lucide-sigma",{"title":261,"icon":262,"path":263,"stem":264,"children":265,"page":6},"Release Notes","i-lucide-rocket","\u002Fen\u002Frelease-notes","en\u002F7.release-notes",[266],{"title":267,"path":268,"stem":269,"icon":262},"Changelog","\u002Fen\u002Frelease-notes\u002Fchangelog","en\u002F7.release-notes\u002F1.changelog",{"id":271,"title":49,"body":272,"description":1282,"extension":1283,"links":1284,"meta":1285,"navigation":1286,"path":50,"seo":1287,"stem":51,"__hash__":1288},"docs_en\u002Fen\u002F2.concepts\u002F4.audit-logs.md",{"type":273,"value":274,"toc":1266},"minimark",[275,279,283,286,290,311,316,416,420,423,520,524,546,553,557,560,684,691,697,701,714,724,727,799,813,817,820,976,982,1144,1148,1151,1173,1177,1180,1202,1206,1209,1231,1235,1262],[276,277,109],"h2",{"id":278},"overview",[280,281,282],"p",{},"Audit logs record administrative and security-relevant activity across your organization: who did what, when, and whether it succeeded. Monospace writes an entry every time an account changes, an invitation is issued, workspace membership changes, or a schema migration is applied.",[280,284,285],{},"Administrators read the log through the system API to review activity, investigate changes, and support compliance reviews.",[276,287,289],{"id":288},"recorded-activity","Recorded Activity",[280,291,292,293,297,298,301,302,306,307,310],{},"Every entry describes one ",[294,295,296],"strong",{},"action"," against one ",[294,299,300],{},"resource",". Monospace records two resource types — ",[303,304,305],"code",{},"user"," and ",[303,308,309],{},"schema"," — and the actions below.",[312,313,315],"h3",{"id":314},"user-activity","User activity",[317,318,319,332],"table",{},[320,321,322],"thead",{},[323,324,325,329],"tr",{},[326,327,328],"th",{},"Action",[326,330,331],{},"What triggers it",[333,334,335,346,356,366,376,386,396,406],"tbody",{},[323,336,337,343],{},[338,339,340],"td",{},[303,341,342],{},"user.create.v1",[338,344,345],{},"A user account or service account is created.",[323,347,348,353],{},[338,349,350],{},[303,351,352],{},"user.update.v1",[338,354,355],{},"A user account or service account is changed, including a user editing their own profile or an administrator editing another user. Records the fields that changed.",[323,357,358,363],{},[338,359,360],{},[303,361,362],{},"user.soft_delete.v1",[338,364,365],{},"A user account or service account is removed.",[323,367,368,373],{},[338,369,370],{},[303,371,372],{},"organization.invite_member.v1",[338,374,375],{},"A new member is invited to the organization or a workspace. Records the invited email, the assigned roles, and the invitation's expiry.",[323,377,378,383],{},[338,379,380],{},[303,381,382],{},"user.join_workspace.v1",[338,384,385],{},"A user or service account is added to a workspace — directly, or by accepting a workspace invitation.",[323,387,388,393],{},[338,389,390],{},[303,391,392],{},"user.remove_workspace.v1",[338,394,395],{},"A member is removed from a workspace. One entry is recorded per member.",[323,397,398,403],{},[338,399,400],{},[303,401,402],{},"user.invite_revoke.v1",[338,404,405],{},"A pending invitation is revoked.",[323,407,408,413],{},[338,409,410],{},[303,411,412],{},"user.invite_renew.v1",[338,414,415],{},"A pending invitation is renewed with a new expiry.",[312,417,419],{"id":418},"authentication-activity","Authentication activity",[280,421,422],{},"These cover the built-in password authentication method.",[317,424,425,433],{},[320,426,427],{},[323,428,429,431],{},[326,430,328],{},[326,432,331],{},[333,434,435,445,467,477,487,500,510],{},[323,436,437,442],{},[338,438,439],{},[303,440,441],{},"auth.login.v1",[338,443,444],{},"A user signs in successfully. Records the auth method, session mode, and — when present — the user agent and referer.",[323,446,447,452],{},[338,448,449],{},[303,450,451],{},"auth.login_failed.v1",[338,453,454,455,458,459,462,463,466],{},"A sign-in attempt fails. Recorded with a ",[303,456,457],{},"failure"," outcome against the attempted email and a generic ",[303,460,461],{},"reason"," (such as ",[303,464,465],{},"invalid_email_or_password","), so it never reveals whether the account exists.",[323,468,469,474],{},[338,470,471],{},[303,472,473],{},"auth.logout.v1",[338,475,476],{},"A user signs out and their refresh session is invalidated.",[323,478,479,484],{},[338,480,481],{},[303,482,483],{},"auth.token_refresh.v1",[338,485,486],{},"A user's access token is refreshed.",[323,488,489,494],{},[338,490,491],{},[303,492,493],{},"auth.password_reset_request.v1",[338,495,496,497,499],{},"A password reset is requested. A request for an unknown email is recorded with a ",[303,498,457],{}," outcome to prevent account enumeration.",[323,501,502,507],{},[338,503,504],{},[303,505,506],{},"auth.password_reset_confirm.v1",[338,508,509],{},"A password reset is completed with a valid token.",[323,511,512,517],{},[338,513,514],{},[303,515,516],{},"auth.password_change.v1",[338,518,519],{},"A signed-in user changes their own password.",[312,521,523],{"id":522},"schema-activity","Schema activity",[317,525,526,534],{},[320,527,528],{},[323,529,530,532],{},[326,531,328],{},[326,533,331],{},[333,535,536],{},[323,537,538,543],{},[338,539,540],{},[303,541,542],{},"schema.migration.v1",[338,544,545],{},"A schema migration is applied to a workspace, recorded after it commits.",[280,547,548,549,552],{},"A migration groups one or more changes to your data model — for example, creating, renaming, or deleting a collection; adding a field, changing its type, or removing it; or defining a relation. The entry's ",[303,550,551],{},"payload"," lists each operation the migration applied.",[276,554,556],{"id":555},"entry-structure","Entry Structure",[280,558,559],{},"Every entry shares a common set of fields.",[317,561,562,572],{},[320,563,564],{},[323,565,566,569],{},[326,567,568],{},"Field",[326,570,571],{},"Description",[333,573,574,584,594,606,625,635,645,663,673],{},[323,575,576,581],{},[338,577,578],{},[303,579,580],{},"id",[338,582,583],{},"Unique identifier for the entry.",[323,585,586,591],{},[338,587,588],{},[303,589,590],{},"timestamp",[338,592,593],{},"When the activity occurred.",[323,595,596,600],{},[338,597,598],{},[303,599,296],{},[338,601,602,603,605],{},"The versioned event type, such as ",[303,604,342],{},".",[323,607,608,613],{},[338,609,610],{},[303,611,612],{},"resourceType",[338,614,615,616,618,619,622,623,605],{},"The kind of resource affected: ",[303,617,305],{},", ",[303,620,621],{},"session",", or ",[303,624,309],{},[323,626,627,632],{},[338,628,629],{},[303,630,631],{},"resourceId",[338,633,634],{},"Identifier of the affected resource. Empty for events that do not target a single resource, such as schema migrations.",[323,636,637,642],{},[338,638,639],{},[303,640,641],{},"actorId",[338,643,644],{},"The user who performed the action. Empty when the action is performed by the system or without a signed-in user.",[323,646,647,652],{},[338,648,649],{},[303,650,651],{},"outcome",[338,653,654,655,618,658,622,661,605],{},"The result: ",[303,656,657],{},"success",[303,659,660],{},"partial_success",[303,662,457],{},[323,664,665,670],{},[338,666,667],{},[303,668,669],{},"workspaceId",[338,671,672],{},"The workspace the activity belongs to, for workspace-scoped events.",[323,674,675,679],{},[338,676,677],{},[303,678,551],{},[338,680,681,682,605],{},"Action-specific detail, returned as native JSON. Its contents vary by ",[303,683,296],{},[280,685,686,687,690],{},"Action names carry a version suffix (",[303,688,689],{},".v1",") so the structure of each event type stays stable for integrations.",[280,692,693,694,696],{},"A ",[303,695,457],{}," outcome is recorded when an operation does not complete — for example, an attempt to remove a workspace member that removes nothing.",[276,698,700],{"id":699},"reading-the-audit-log","Reading the Audit Log",[280,702,703,704,707,708,713],{},"Audit logs are read through the system API. Reading them requires the ",[303,705,706],{},"auditLog:read"," entitlement, which organization administrators have. See ",[709,710,712],"a",{"href":711},"\u002Fconcepts\u002Faccess-permissions","Access & Permissions"," for how entitlements are granted.",[280,715,716,720,721],{},[717,718],"http-method",{"method":719},"GET"," ",[303,722,723],{},"\u002Fapi\u002Fsystem\u002Faudit-logs",[280,725,726],{},"The endpoint accepts the same query parameters as the rest of the API:",[317,728,729,738],{},[320,730,731],{},[323,732,733,736],{},[326,734,735],{},"Parameter",[326,737,571],{},[333,739,740,753,766,779,789],{},[323,741,742,747],{},[338,743,744],{},[303,745,746],{},"fields",[338,748,749,750,605],{},"The fields to return. Required — there is no implicit select-all, and an empty selection is rejected. See ",[709,751,139],{"href":752},"\u002Fdeveloper\u002Fapi\u002Ffield-selection",[323,754,755,760],{},[338,756,757],{},[303,758,759],{},"filter",[338,761,762,763,605],{},"Return only entries matching a condition. See ",[709,764,134],{"href":765},"\u002Fdeveloper\u002Fapi\u002Ffiltering",[323,767,768,773],{},[338,769,770],{},[303,771,772],{},"sort",[338,774,775,776,605],{},"Order the entries. See ",[709,777,144],{"href":778},"\u002Fdeveloper\u002Fapi\u002Fsorting-pagination",[323,780,781,786],{},[338,782,783],{},[303,784,785],{},"limit",[338,787,788],{},"Maximum number of entries to return.",[323,790,791,796],{},[338,792,793],{},[303,794,795],{},"offset",[338,797,798],{},"Number of entries to skip, for pagination.",[280,800,801,802,805,806,618,808,618,810,812],{},"Every request must select fields — pass ",[303,803,804],{},"fields=*"," to return all of them, or name the ones you want, as shown below. Field names use the API spelling (",[303,807,612],{},[303,809,641],{},[303,811,669],{},"), not the underlying column names.",[312,814,816],{"id":815},"recent-activity","Recent activity",[280,818,819],{},"Return the 50 most recent entries, newest first:",[821,822,823,860],"code-group",{},[824,825,831],"pre",{"className":826,"code":827,"filename":828,"language":829,"meta":830,"style":830},"language-bash shiki shiki-themes monospace-light monospace-light monospace-dark","curl -g \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=id,timestamp,action,resourceType,resourceId,actorId,outcome,workspaceId,payload&sort[0][timestamp][direction]=desc&limit=50\" \\\n  -H \"Authorization: Bearer YOUR_API_KEY\"\n","curl","bash","",[303,832,833,851],{"__ignoreMap":830},[834,835,838,841,844,848],"span",{"class":836,"line":837},"line",1,[834,839,828],{"class":840},"ssBNi",[834,842,843],{"class":840}," -g",[834,845,847],{"class":846},"suKVh"," \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=id,timestamp,action,resourceType,resourceId,actorId,outcome,workspaceId,payload&sort[0][timestamp][direction]=desc&limit=50\"",[834,849,850],{"class":840}," \\\n",[834,852,854,857],{"class":836,"line":853},2,[834,855,856],{"class":840},"  -H",[834,858,859],{"class":846}," \"Authorization: Bearer YOUR_API_KEY\"\n",[824,861,866],{"className":862,"code":863,"filename":864,"language":865,"meta":830,"style":830},"language-ts shiki shiki-themes monospace-light monospace-light monospace-dark","const response = await fetch(\n  'https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=id,timestamp,action,resourceType,resourceId,actorId,outcome,workspaceId,payload&sort[0][timestamp][direction]=desc&limit=50',\n  {\n    headers: {\n      Authorization: 'Bearer YOUR_API_KEY',\n    },\n  },\n);\n\nconst { data } = await response.json();\n","fetch","ts",[303,867,868,890,898,904,910,921,927,933,939,946],{"__ignoreMap":830},[834,869,870,874,877,880,883,886],{"class":836,"line":837},[834,871,873],{"class":872},"sLVBU","const",[834,875,876],{"class":840}," response",[834,878,879],{"class":872}," =",[834,881,882],{"class":872}," await",[834,884,885],{"class":840}," fetch",[834,887,889],{"class":888},"sTMul","(\n",[834,891,892,895],{"class":836,"line":853},[834,893,894],{"class":846},"  'https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=id,timestamp,action,resourceType,resourceId,actorId,outcome,workspaceId,payload&sort[0][timestamp][direction]=desc&limit=50'",[834,896,897],{"class":888},",\n",[834,899,901],{"class":836,"line":900},3,[834,902,903],{"class":888},"  {\n",[834,905,907],{"class":836,"line":906},4,[834,908,909],{"class":888},"    headers: {\n",[834,911,913,916,919],{"class":836,"line":912},5,[834,914,915],{"class":888},"      Authorization: ",[834,917,918],{"class":846},"'Bearer YOUR_API_KEY'",[834,920,897],{"class":888},[834,922,924],{"class":836,"line":923},6,[834,925,926],{"class":888},"    },\n",[834,928,930],{"class":836,"line":929},7,[834,931,932],{"class":888},"  },\n",[834,934,936],{"class":836,"line":935},8,[834,937,938],{"class":888},");\n",[834,940,942],{"class":836,"line":941},9,[834,943,945],{"emptyLinePlaceholder":944},true,"\n",[834,947,949,951,954,957,960,963,965,968,970,973],{"class":836,"line":948},10,[834,950,873],{"class":872},[834,952,953],{"class":888}," { ",[834,955,956],{"class":840},"data",[834,958,959],{"class":888}," } ",[834,961,962],{"class":872},"=",[834,964,882],{"class":872},[834,966,876],{"class":967},"sNJ9c",[834,969,605],{"class":888},[834,971,972],{"class":840},"json",[834,974,975],{"class":888},"();\n",[280,977,978,979,981],{},"Each matching entry is returned under ",[303,980,956],{},":",[824,983,987],{"className":984,"code":985,"filename":986,"language":972,"meta":830,"style":830},"language-json shiki shiki-themes monospace-light monospace-light monospace-dark","{\n  \"data\": [\n    {\n      \"id\": \"0a9e7c1b-6d2f-4c8a-9f3e-1b2c3d4e5f6a\",\n      \"timestamp\": \"2026-06-23T10:14:22Z\",\n      \"action\": \"user.create.v1\",\n      \"resourceType\": \"user\",\n      \"resourceId\": \"2c1a4e9b-8d7f-4a6b-9c0e-5f4d3a2b1c0d\",\n      \"actorId\": \"7f6b2d10-3e4a-4b5c-8d9e-0a1b2c3d4e5f\",\n      \"outcome\": \"success\",\n      \"workspaceId\": null,\n      \"payload\": { \"email\": \"alex@example.com\" }\n    }\n  ]\n}\n","response.json",[303,988,989,994,1003,1008,1021,1033,1045,1057,1069,1081,1093,1106,1126,1132,1138],{"__ignoreMap":830},[834,990,991],{"class":836,"line":837},[834,992,993],{"class":888},"{\n",[834,995,996,1000],{"class":836,"line":853},[834,997,999],{"class":998},"snHjA","  \"data\"",[834,1001,1002],{"class":888},": [\n",[834,1004,1005],{"class":836,"line":900},[834,1006,1007],{"class":888},"    {\n",[834,1009,1010,1013,1016,1019],{"class":836,"line":906},[834,1011,1012],{"class":998},"      \"id\"",[834,1014,1015],{"class":888},": ",[834,1017,1018],{"class":846},"\"0a9e7c1b-6d2f-4c8a-9f3e-1b2c3d4e5f6a\"",[834,1020,897],{"class":888},[834,1022,1023,1026,1028,1031],{"class":836,"line":912},[834,1024,1025],{"class":998},"      \"timestamp\"",[834,1027,1015],{"class":888},[834,1029,1030],{"class":846},"\"2026-06-23T10:14:22Z\"",[834,1032,897],{"class":888},[834,1034,1035,1038,1040,1043],{"class":836,"line":923},[834,1036,1037],{"class":998},"      \"action\"",[834,1039,1015],{"class":888},[834,1041,1042],{"class":846},"\"user.create.v1\"",[834,1044,897],{"class":888},[834,1046,1047,1050,1052,1055],{"class":836,"line":929},[834,1048,1049],{"class":998},"      \"resourceType\"",[834,1051,1015],{"class":888},[834,1053,1054],{"class":846},"\"user\"",[834,1056,897],{"class":888},[834,1058,1059,1062,1064,1067],{"class":836,"line":935},[834,1060,1061],{"class":998},"      \"resourceId\"",[834,1063,1015],{"class":888},[834,1065,1066],{"class":846},"\"2c1a4e9b-8d7f-4a6b-9c0e-5f4d3a2b1c0d\"",[834,1068,897],{"class":888},[834,1070,1071,1074,1076,1079],{"class":836,"line":941},[834,1072,1073],{"class":998},"      \"actorId\"",[834,1075,1015],{"class":888},[834,1077,1078],{"class":846},"\"7f6b2d10-3e4a-4b5c-8d9e-0a1b2c3d4e5f\"",[834,1080,897],{"class":888},[834,1082,1083,1086,1088,1091],{"class":836,"line":948},[834,1084,1085],{"class":998},"      \"outcome\"",[834,1087,1015],{"class":888},[834,1089,1090],{"class":846},"\"success\"",[834,1092,897],{"class":888},[834,1094,1096,1099,1101,1104],{"class":836,"line":1095},11,[834,1097,1098],{"class":998},"      \"workspaceId\"",[834,1100,1015],{"class":888},[834,1102,1103],{"class":840},"null",[834,1105,897],{"class":888},[834,1107,1109,1112,1115,1118,1120,1123],{"class":836,"line":1108},12,[834,1110,1111],{"class":998},"      \"payload\"",[834,1113,1114],{"class":888},": { ",[834,1116,1117],{"class":998},"\"email\"",[834,1119,1015],{"class":888},[834,1121,1122],{"class":846},"\"alex@example.com\"",[834,1124,1125],{"class":888}," }\n",[834,1127,1129],{"class":836,"line":1128},13,[834,1130,1131],{"class":888},"    }\n",[834,1133,1135],{"class":836,"line":1134},14,[834,1136,1137],{"class":888},"  ]\n",[834,1139,1141],{"class":836,"line":1140},15,[834,1142,1143],{"class":888},"}\n",[312,1145,1147],{"id":1146},"filter-by-action","Filter by action",[280,1149,1150],{},"Return only schema migrations:",[824,1152,1154],{"className":826,"code":1153,"filename":828,"language":829,"meta":830,"style":830},"curl -g \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=timestamp,action,resourceType,workspaceId&filter[action][_eq]=schema.migration.v1\" \\\n  -H \"Authorization: Bearer YOUR_API_KEY\"\n",[303,1155,1156,1167],{"__ignoreMap":830},[834,1157,1158,1160,1162,1165],{"class":836,"line":837},[834,1159,828],{"class":840},[834,1161,843],{"class":840},[834,1163,1164],{"class":846}," \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=timestamp,action,resourceType,workspaceId&filter[action][_eq]=schema.migration.v1\"",[834,1166,850],{"class":840},[834,1168,1169,1171],{"class":836,"line":853},[834,1170,856],{"class":840},[834,1172,859],{"class":846},[312,1174,1176],{"id":1175},"filter-by-actor","Filter by actor",[280,1178,1179],{},"Return every action a specific user performed:",[824,1181,1183],{"className":826,"code":1182,"filename":828,"language":829,"meta":830,"style":830},"curl -g \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=timestamp,action,resourceType,resourceId,outcome&filter[actorId][_eq]=7f6b2d10-3e4a-4b5c-8d9e-0a1b2c3d4e5f\" \\\n  -H \"Authorization: Bearer YOUR_API_KEY\"\n",[303,1184,1185,1196],{"__ignoreMap":830},[834,1186,1187,1189,1191,1194],{"class":836,"line":837},[834,1188,828],{"class":840},[834,1190,843],{"class":840},[834,1192,1193],{"class":846}," \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=timestamp,action,resourceType,resourceId,outcome&filter[actorId][_eq]=7f6b2d10-3e4a-4b5c-8d9e-0a1b2c3d4e5f\"",[834,1195,850],{"class":840},[834,1197,1198,1200],{"class":836,"line":853},[834,1199,856],{"class":840},[834,1201,859],{"class":846},[312,1203,1205],{"id":1204},"failed-operations","Failed operations",[280,1207,1208],{},"Return only entries that did not succeed:",[824,1210,1212],{"className":826,"code":1211,"filename":828,"language":829,"meta":830,"style":830},"curl -g \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=timestamp,action,resourceType,resourceId,outcome&filter[outcome][_eq]=failure\" \\\n  -H \"Authorization: Bearer YOUR_API_KEY\"\n",[303,1213,1214,1225],{"__ignoreMap":830},[834,1215,1216,1218,1220,1223],{"class":836,"line":837},[834,1217,828],{"class":840},[834,1219,843],{"class":840},[834,1221,1222],{"class":846}," \"https:\u002F\u002Fexample.monospace.io\u002Fapi\u002Fsystem\u002Faudit-logs?fields=timestamp,action,resourceType,resourceId,outcome&filter[outcome][_eq]=failure\"",[834,1224,850],{"class":840},[834,1226,1227,1229],{"class":836,"line":853},[834,1228,856],{"class":840},[834,1230,859],{"class":846},[276,1232,1234],{"id":1233},"see-also","See Also",[1236,1237,1238,1246,1252,1257],"ul",{},[1239,1240,1241,1243,1244],"li",{},[709,1242,712],{"href":711}," — How roles and entitlements control access, including ",[303,1245,706],{},[1239,1247,1248,1251],{},[709,1249,222],{"href":1250},"\u002Freference\u002Fapi-reference\u002Fsystem-endpoints"," — The full catalog of administrative and organizational API endpoints",[1239,1253,1254,1256],{},[709,1255,134],{"href":765}," — Operators and conditions for narrowing results",[1239,1258,1259,1261],{},[709,1260,144],{"href":778}," — Ordering entries and paging through large result sets",[1263,1264,1265],"style",{},"html pre.shiki code .ssBNi, html code.shiki .ssBNi{--shiki-light:#1659E9;--shiki-default:#1659E9;--shiki-dark:#94B3F5}html pre.shiki code .suKVh, html code.shiki .suKVh{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#F8FAFC}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sLVBU, html code.shiki .sLVBU{--shiki-light:#0891B2;--shiki-default:#0891B2;--shiki-dark:#22D3EE}html pre.shiki code .sTMul, html code.shiki .sTMul{--shiki-light:#1F2937;--shiki-default:#1F2937;--shiki-dark:#94A3B8}html pre.shiki code .sNJ9c, html code.shiki .sNJ9c{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#E2E8F0}html pre.shiki code .snHjA, html code.shiki .snHjA{--shiki-light:#124BC4;--shiki-default:#124BC4;--shiki-dark:#5B8EF4}",{"title":830,"searchDepth":853,"depth":853,"links":1267},[1268,1269,1274,1275,1281],{"id":278,"depth":853,"text":109},{"id":288,"depth":853,"text":289,"children":1270},[1271,1272,1273],{"id":314,"depth":900,"text":315},{"id":418,"depth":900,"text":419},{"id":522,"depth":900,"text":523},{"id":555,"depth":853,"text":556},{"id":699,"depth":853,"text":700,"children":1276},[1277,1278,1279,1280],{"id":815,"depth":900,"text":816},{"id":1146,"depth":900,"text":1147},{"id":1175,"depth":900,"text":1176},{"id":1204,"depth":900,"text":1205},{"id":1233,"depth":853,"text":1234},"Audit logs record administrative and security-relevant activity across your organization for review and investigation.","md",null,{},{"icon":52},{"title":49,"description":1282},"wYZwRj-ACpKUFd60kyIQOYav7uhSEyht22JyN9ht0zI",[1290,1292],{"title":44,"path":45,"stem":46,"description":1291,"icon":47,"children":-1},"Learn about Access & Permissions.",{"title":54,"path":55,"stem":56,"description":1293,"icon":57,"children":-1},"Learn about database introspection.",1784053978672]