Audit Log
Path: /admin/audit · Sidebar: Administration → Audit Log
A tamper-evident record of everything that happens in the platform - essential for compliance, incident response and accountability.
What's recorded
- User actions - logins, scans started, findings triaged, risk accepted, settings changed.
- API calls - programmatic actions via
apt_tokens. - System events - feeds updated, gates evaluated, exports generated.
Each entry carries the who (user/token), what (action), when (timestamp, shown in GMT+4) and often the where (IP) and affected object.
Using the audit log
- Filter by user, action type, object or date range.
- Investigate - "who accepted the risk on this vulnerability?" or "when was this target's auth changed?".
- Export for auditors as evidence of governance and change control.
Compliance evidence
The audit log is a key piece of evidence for SOC 2 / ISO 27001 change-management and access controls - pair it with the Compliance module.