Trace execution and audit logs
This page is for operators, administrators and auditors investigating execution results. Compare approved content with execution results and trace issued resources through revocation.
Check the approved plan
Section titled “Check the approved plan”- Open “Plan” and “Route” in the request record. You can review changes, cost, expiry and approval status.
- Check the plan hash. Execution is bound to content whose saved plan hash matches the approval-time hash, so you can identify the approved content.
- If changes are needed, ask the requester to seek approval through a new request. The revised content can receive a new decision.
The hash identifies the content being approved, including runbook commands and execution targets. A mismatch stops automatic execution; an expiry revocation mismatch goes to a human revocation task.
Check execution methods and results
Section titled “Check execution methods and results”- Review the request’s execution result. You can identify automatic execution through a supported connection or runbook work completed by an assignee with evidence.
- For a runbook task, check the assignee and evidence. You can review what the assignee recorded on completion.
- For an operation with steps, open “Execution log” in Operations. You can check actors, timestamps, exit codes and output excerpts.
Unsupported execution, missing connections and supported failure cases fall back to runbook work. Task completion requires the assignee’s authority and evidence.
Follow audit events over time
Section titled “Follow audit events over time”- Open “Audit” in the request record and find
request.created. It identifies the start of the request. - Read approval-related events. Approvals and rejections are
step.approvedandstep.rejected, and a return isrequest.returned. When a delegate makes the decision, the same event carriesdelegated_from_user_id. Escalation isapproval.escalated. - Review
execution.*, runbookmanual.*and stepoperation.*events. You can trace execution results and fallback handling. - In the ledger record’s “Audit log”, check
grant.created,grant.revokedandgrant.expired_revoked. You can connect grants and revocations to their basis request.
The overall flow is request creation → approval decision → execution → grant and revocation. Completion records grant.created before execution.succeeded. Use the recorded order when reading the screen or CSV rather than assuming it follows this conceptual sequence.
Choose where to investigate
Section titled “Choose where to investigate”| What to check | Where |
|---|---|
| Approved changes, cost, expiry and route | Execution plan and route in the request record |
| Request decisions and execution history | Audit in the request record |
| Step results, actors and output | Operations execution log |
| Grant basis, subject, monthly cost and revocation | Record in the issued resource ledger |
| Organization-wide events for a period | Audit CSV from the dashboard |
Audit events are append-only. The screens do not allow editing or deletion. See Audit events for event names and meanings.