SISuperintelligenceDocs

Search docs

Search every page of the documentation.

API reference

Audit log

Read an organization's audit log.

See Audit log for every recorded action.

GET /v1/orgs/:orgId/audit

One page of the audit log, newest first. Filter by action (an action or a category), actor or target. The first page also returns retentionDays.

Auth: user access token or platform agent key · Scope: audit:read

Path parameterDescription
:orgIdOrganization id (org_…).
Query parameterTypeRequiredDefaultNotes
cursorstringNoup to 4,096 characters
actionstringNomatches ^[a-z_]{1,32}(\.[a-z_]{1,32})?$
actorstringNo1–512 characters
targetstringNomatches ^[a-z_]{1,32}:[^\s]{1,512}$
limitintegerNo501–100; coerced from a string

Response 200

{
  events: {
    eventId: string
    orgId: string
    action: string
    actor: {
      type: "user" | "device" | "key" | "system"
      id: string
      label?: string
    }
    target: {
      type: string
      id: string
      label?: string
    }
    metadata?: {
      [key: string]: unknown
    }
    ip?: string
    userAgent?: string
    createdAt: number
  }[]
  cursor: null | string
  retentionDays?: number
}

Errors

StatusMessage
400Invalid cursor