Audit Logs: Metric Reference
This page is the source of truth for the in-app Explain this panels on the
Audit Logs page (/audit-logs). Each section is written
once as a content partial under _explain/audit-logs/ and rendered both here and inside the app's
info panel (scripts/build-explain.mjs compiles the registry).
Audit Logs are gated by the ViewAuditLogs permission, held by Admin and SuperAdmin by default.
Track API access and user activity across your organization.
How it's calculated
- The page requires the ViewAuditLogs permission. Admin and SuperAdmin hold it by default — the audience is the permission, not a hardcoded role check, so a future role or a custom grant could hold it too.
- Every recorded action carries the acting user, their role at the time, the HTTP method, route, controller, and action, an optional entity reference, the response status, and duration — sourced from API request activity, not from database-level auditing on monitored engines.
- The page opens on the Last 24 Hours window by default, distinct from the shared time-window default used elsewhere in the product.
Reading it
Start from the Activity table's filters to scope a window and narrow by method, controller, or entity, then open a row for the full Event Detail — including request context — before drawing conclusions from the summary columns alone.
Activity
Every recorded action in the selected time window, one row per API request.
How it's calculated
- Columns: Time, User, Method, Route, Controller, Entity, Status, and duration in milliseconds. Entity shows an em dash when the action isn't tied to a specific entity.
- Defaults to the Last 24 Hours window, set independently of the shared time-window default used on explorer pages elsewhere in the product.
- Every column has its own header-menu filter: Time reopens the time-range picker, User and Route are text matches, Method is a multi-select of HTTP verbs, Controller and Entity are populated from a distinct query over the whole window (not just the loaded page), and Status and duration are min/max ranges.
- Rows are paginated; selecting a row opens its Event Detail panel alongside the table rather than navigating away.
Reading it
Controller and Entity filter options reflect the selected window as a whole, so a value can appear in the dropdown before its row has loaded onto the current page — keep paging or narrow further rather than assuming the filter is wrong.
Event Detail
The full context for one recorded action, opened by selecting its row.
How it's calculated
- Always shown: Time, User (email, falling back to user ID), Role (the user's role at the time of the action), Controller, Action, Duration in milliseconds, and an Impersonating badge when the action was performed through an impersonation session.
- Shown only when present: Entity (type and ID), Client IP, a query string block, a request body block, and a user agent string.
- Request body is parsed and pretty-printed as JSON when possible; sensitive values are sanitized before they're stored, so the panel never exposes secrets or monitored-database content — only what type of change was made.
Reading it
Check the Impersonating badge before treating an action as the named user's own — it distinguishes direct activity from actions taken on a member's behalf during support or administrative access. Use Client IP and User Agent together when tracing where a request actually originated.