Skip to main content

Audit log

See who did what across your organization, including actions LuumenAI takes on your behalf.

J
Written by Joseph Howell

The audit log is a record of every action taken through Luumen in every workspace, whether it was performed by a person or by LuumenAI. For administrators and security teams, this provides one accountable record of change: who acted, what changed, and whether it succeeded, without piecing it together from application logs. Events cannot be edited or deleted, so the log stands as evidence for access reviews, incident investigation, and compliance.

View Audit Log

Requirements

  • Owner or Admin role. The audit log does not appear for Members roles.

  1. Select Audit in the left navigation.

  2. Events are listed by day, newest first. Each row shows Time, Event, Actor, Target, Outcome, and Evidence. Time uses your computer's timezone.

  3. Expand a row to see an Event's target and workspace. For LuumenAI actions, this also shows the run, with a View Run link.

The audit log listing events by time, with the event, actor, outcome, and evidence for each

What is Recorded

Each Event names the Actor, the record it affected and the Outcome. When LuumenAI acts, the event names both LuumenAI and the person it acted for. When a value changes, such as a role or a name, the event records both the old and new values. Requesting an AI summary of the audit log is itself a recorded event.

Events cover:

  • Membership and access. Invitations sent, organization and workspace role changes, and workspace access grants and revocations, including changes that were blocked.

  • Passwords and sign-in security. Password changes and resets, sign-outs, and SSO configuration changes.

  • Stored credentials and API keys. Credentials created, updated, rotated, revoked and restored. API keys created and revoked.

  • Support access. Requests for Luumen support to access your organization, approvals, and the start and end of each support session.

  • Organization and workspace lifecycle. Organizations and workspaces created, renamed, settings changed, and deleted.

  • LuumenAI. Conversations started, messages sent, runs started, completed, failed, or escalated, approval requests and decisions, and the actions LuumenAI takes. Approval and action events carry a risk level: low, medium, high or, critical.

  • Skills. Created, published, unpublished, archived, and deleted.

  • Integration connections. Created, enabled, disabled, reauthorized, and removed.

  • Hosts. Added, updated, and removed, including jump hosts. Adding a Host to a group or removing it records as a Host update.

  • Billing. Subscription changes.

  • Audit summaries. Every summary request

What is Not Recorded

The audit log records that actions happened, not their content:

  1. Conversation content. Prompts and responses are not stored in audit events.

  2. Command text and output. Anything typed or run in a terminal stays on your machine; events record the action and its outcome, not the command itself.

  3. Secrets. Credential events record lifecycle metadata only. Passwords, keys, and tokens never appear in any event.

The audit log is a record of consequential actions taken through Luumen. It is not a transcript of your shell or your conversations.

Filter and Search the Audit Log

  1. Use the filters above the list: Actor, Target, Event, Outcome, Run, Conversation, Evidence, and date. Target, Run, and Conversation appear once there's something to filter by.

  2. Choose a date range: Last 24 hours, Last 7 days, Last 30 days, or a custom range.

  3. Enter text in the search box to match event names and the names of actors and targets. Search doesn't match IDs.

  4. Combine filters to narrow further. Outcome values are Succeeded, Failed, Denied, and Cancelled.

AI Summaries in the Audit Log

Filter the log to one run, one conversation, or any set of events, and a summary bar appears above the list. Nothing is generated until you click the button.

  • A run or conversation can be summarized up to 200 events. Any other filtered view can be summarized up to 2,000 events. A large view is read in full, but the summary cites at most 100 individual events.

  • Over the limit, the button is disabled and the bar tells you how many events are selected. Narrow the filters to bring the count down.

  • If you add other filters or a search to a single run or conversation, no summary is offered.

  • LuumenAI writes the headline and the summary text. Everything under Key facts, such as status, workspaces, targets, and actors, comes straight from the events.

  • The panel shows when the summary was generated.

Expanding the Audit Log

The audit log is designed to grow with your governance requirements. If your organization needs additional views of this data, such as separating AI activity or host activity into their own views, contact us.

Enterprise customers can also work with us to stream audit events to their SIEM or other security tooling, so Luumen activity appears alongside the rest of your security data.

Retention and Export

Events are append-only. Nothing in Luumen edits or deletes an event once it's written, and an event stays in the log even after the host, credential, or member it concerns is deleted. To export please contact [email protected]

Related articles

Did this answer your question?