Skip to main content

Audit Log

Path: /admin/audit · Sidebar: Administration → Audit Log

A tamper-evident record of everything that happens in the platform - essential for compliance, incident response and accountability.

What's recorded

  • User actions - logins, scans started, findings triaged, risk accepted, settings changed.
  • API calls - programmatic actions via apt_ tokens.
  • System events - feeds updated, gates evaluated, exports generated.

Each entry carries the who (user/token), what (action), when (timestamp, shown in GMT+4) and often the where (IP) and affected object.

Using the audit log

  • Filter by user, action type, object or date range.
  • Investigate - "who accepted the risk on this vulnerability?" or "when was this target's auth changed?".
  • Export for auditors as evidence of governance and change control.
Compliance evidence

The audit log is a key piece of evidence for SOC 2 / ISO 27001 change-management and access controls - pair it with the Compliance module.