Scrydon
Security

Audit Log catalogue

The complete set of audit, workflow, and integrity events recorded by Scrydon.

Scrydon accepts only actions and resource types in this catalogue. The page is rendered from the same registry used by server validation, so an event value cannot be accepted without appearing here.

See Audit logging for retention, export, Log Receiver forwarding, and the common envelope carried by every event type.

Audit actions

Authorization entries cover every combination of action (read, write, delete, execute, admin, retire) and outcome (GRANTED, DENIED, INDETERMINATE). One decision produces one entry. The evaluated subject is stored in the bounded decision evidence, while producer identifies the authenticated Scrydon workload that submitted it.

ActionRegistry keyFamilyDescriptionStatus
SECRET_CREATESECRET_CREATEintegrationRecords secret create.Active
SECRET_UPDATESECRET_UPDATEintegrationRecords secret update.Active
SECRET_DELETESECRET_DELETEintegrationRecords secret delete.Active
SECRET_ACCESSSECRET_ACCESSintegrationRecords secret access.Active
PROVIDER_CREATEPROVIDER_CREATEintegrationRecords provider create.Active
PROVIDER_UPDATEPROVIDER_UPDATEintegrationRecords provider update.Active
PROVIDER_DELETEPROVIDER_DELETEintegrationRecords provider delete.Active
PROVIDER_TESTPROVIDER_TESTintegrationRecords provider test.Active
RESOURCE_CREATERESOURCE_CREATEdataRecords resource create.Active
RESOURCE_UPDATERESOURCE_UPDATEdataRecords resource update.Active
RESOURCE_DELETERESOURCE_DELETEdataRecords resource delete.Active
RESOURCE_ACCESSRESOURCE_ACCESSdataRecords resource access.Active
ontology.entity.changedONTOLOGY_ENTITY_CHANGEDoperationsRecords ontology entity changed.Active
ontology.effect.requestedONTOLOGY_EFFECT_REQUESTEDoperationsRecords ontology effect requested.Active
AUTH_READ_DENIEDAUTH_READ_DENIEDauthorizationRecords auth read denied.Active
AUTH_WRITE_DENIEDAUTH_WRITE_DENIEDauthorizationRecords auth write denied.Active
AUTH_DELETE_DENIEDAUTH_DELETE_DENIEDauthorizationRecords auth delete denied.Active
AUTH_EXECUTE_DENIEDAUTH_EXECUTE_DENIEDauthorizationRecords auth execute denied.Active
AUTH_ADMIN_DENIEDAUTH_ADMIN_DENIEDauthorizationRecords auth admin denied.Active
AUTH_RETIRE_DENIEDAUTH_RETIRE_DENIEDauthorizationRecords auth retire denied.Active
AUTH_READ_GRANTEDAUTH_READ_GRANTEDauthorizationRecords auth read granted.Active
AUTH_WRITE_GRANTEDAUTH_WRITE_GRANTEDauthorizationRecords auth write granted.Active
AUTH_DELETE_GRANTEDAUTH_DELETE_GRANTEDauthorizationRecords auth delete granted.Active
AUTH_EXECUTE_GRANTEDAUTH_EXECUTE_GRANTEDauthorizationRecords auth execute granted.Active
AUTH_ADMIN_GRANTEDAUTH_ADMIN_GRANTEDauthorizationRecords auth admin granted.Active
AUTH_RETIRE_GRANTEDAUTH_RETIRE_GRANTEDauthorizationRecords auth retire granted.Active
AUTH_READ_INDETERMINATEAUTH_READ_INDETERMINATEauthorizationRecords auth read indeterminate.Active
AUTH_WRITE_INDETERMINATEAUTH_WRITE_INDETERMINATEauthorizationRecords auth write indeterminate.Active
AUTH_DELETE_INDETERMINATEAUTH_DELETE_INDETERMINATEauthorizationRecords auth delete indeterminate.Active
AUTH_EXECUTE_INDETERMINATEAUTH_EXECUTE_INDETERMINATEauthorizationRecords auth execute indeterminate.Active
AUTH_ADMIN_INDETERMINATEAUTH_ADMIN_INDETERMINATEauthorizationRecords auth admin indeterminate.Active
AUTH_RETIRE_INDETERMINATEAUTH_RETIRE_INDETERMINATEauthorizationRecords auth retire indeterminate.Active
EXECUTION_GRANT_CREATEDEXECUTION_GRANT_CREATEDauthorizationRecords execution grant created.Active
EXECUTION_GRANT_REJECTEDEXECUTION_GRANT_REJECTEDauthorizationRecords execution grant rejected.Active
EXECUTION_GRANT_BOUNDEXECUTION_GRANT_BOUNDauthorizationRecords execution grant bound.Active
EXECUTION_GRANT_DERIVEDEXECUTION_GRANT_DERIVEDauthorizationRecords execution grant derived.Active
EXECUTION_GRANT_VALIDATEDEXECUTION_GRANT_VALIDATEDauthorizationRecords execution grant validated.Active
EXECUTION_GRANT_REVOKEDEXECUTION_GRANT_REVOKEDauthorizationRecords execution grant revoked.Active
EXECUTION_GRANT_EXPIREDEXECUTION_GRANT_EXPIREDauthorizationRecords execution grant expired.Active
AUTHORIZATION_CONTEXT_CREATEDAUTHORIZATION_CONTEXT_CREATEDoperationsRecords authorization context created.Active
AUTHORIZATION_CONTEXT_REAUTHORIZEDAUTHORIZATION_CONTEXT_REAUTHORIZEDoperationsRecords authorization context reauthorized.Active
AUTHORIZATION_CONTEXT_RESOLVEDAUTHORIZATION_CONTEXT_RESOLVEDoperationsRecords authorization context resolved.Active
AUTHORIZATION_CONTEXT_REJECTEDAUTHORIZATION_CONTEXT_REJECTEDoperationsRecords authorization context rejected.Active
AUTHORIZATION_CONTEXT_REVOKEDAUTHORIZATION_CONTEXT_REVOKEDoperationsRecords authorization context revoked.Active
AUTHORIZATION_CONTEXT_EXPIREDAUTHORIZATION_CONTEXT_EXPIREDoperationsRecords authorization context expired.Active
authz.audit.policy.updatedAUTHZ_AUDIT_POLICY_UPDATEDauthorizationRecords authz audit policy updated.Legacy read-only
isolation.policy.updatedISOLATION_POLICY_UPDATEDauthorizationRecords isolation policy updated.Active
AGENT_EXECUTION_ISOLATION_RELAXEDAGENT_EXECUTION_ISOLATION_RELAXEDoperationsRecords agent execution isolation relaxed.Active
INTEGRATION_ENTITLEMENT_MODE_CHANGEINTEGRATION_ENTITLEMENT_MODE_CHANGEauthorizationRecords integration entitlement mode change.Active
INTEGRATION_ENTITLEMENT_GRANTINTEGRATION_ENTITLEMENT_GRANTauthorizationRecords integration entitlement grant.Active
INTEGRATION_ENTITLEMENT_REVOKEINTEGRATION_ENTITLEMENT_REVOKEauthorizationRecords integration entitlement revoke.Active
INTEGRATION_ENTITLEMENT_UPDATEINTEGRATION_ENTITLEMENT_UPDATEauthorizationRecords integration entitlement update.Active
INTEGRATION_ACCESS_DENIEDINTEGRATION_ACCESS_DENIEDintegrationRecords integration access denied.Active
INTEGRATION_CREDENTIAL_RESOLVEDINTEGRATION_CREDENTIAL_RESOLVEDintegrationRecords integration credential resolved.Active
INTEGRATION_UPGRADEDINTEGRATION_UPGRADEDintegrationRecords integration upgraded.Active
INTEGRATION_ROLLED_BACKINTEGRATION_ROLLED_BACKintegrationRecords integration rolled back.Active
INTEGRATION_ENABLEINTEGRATION_ENABLEintegrationRecords integration enable.Active
INTEGRATION_DISABLEINTEGRATION_DISABLEintegrationRecords integration disable.Active
INTEGRATION_DEPRECATEINTEGRATION_DEPRECATEintegrationRecords integration deprecate.Active
INTEGRATION_CANCEL_DEPRECATIONINTEGRATION_CANCEL_DEPRECATIONintegrationRecords integration cancel deprecation.Active
integration.execution.startedINTEGRATION_EXECUTION_STARTEDintegrationRecords integration execution started.Active
integration.execution.succeededINTEGRATION_EXECUTION_SUCCEEDEDintegrationRecords integration execution succeeded.Active
integration.execution.failedINTEGRATION_EXECUTION_FAILEDintegrationRecords integration execution failed.Active
MCP_TOOL_EXECUTEDMCP_TOOL_EXECUTEDintegrationRecords mcp tool executed.Active
MCP_SERVER_AVAILABILITY_CHANGEDMCP_SERVER_AVAILABILITY_CHANGEDintegrationRecords mcp server availability changed.Active
a2a.publication.createdA2A_PUBLICATION_CREATEDoperationsRecords a2a publication created.Active
a2a.publication.updatedA2A_PUBLICATION_UPDATEDoperationsRecords a2a publication updated.Active
a2a.publication.republishedA2A_PUBLICATION_REPUBLISHEDoperationsRecords a2a publication republished.Active
a2a.publication.unpublishedA2A_PUBLICATION_UNPUBLISHEDoperationsRecords a2a publication unpublished.Active
a2a.task.createdA2A_TASK_CREATEDoperationsRecords a2a task created.Active
a2a.task.canceledA2A_TASK_CANCELEDoperationsRecords a2a task canceled.Active
a2a.push_config.createdA2A_PUSH_CONFIG_CREATEDoperationsRecords a2a push config created.Active
a2a.push_config.deletedA2A_PUSH_CONFIG_DELETEDoperationsRecords a2a push config deleted.Active
a2a.push_delivery.dead_letteredA2A_PUSH_DELIVERY_DEAD_LETTEREDoperationsRecords a2a push delivery dead lettered.Active
pack.catalog.uploadedPACK_CATALOG_UPLOADEDintegrationRecords pack catalog uploaded.Active
pack.catalog.retiredPACK_CATALOG_RETIREDintegrationRecords pack catalog retired.Active
pack.environment.enabledPACK_ENVIRONMENT_ENABLEDintegrationRecords pack environment enabled.Active
pack.environment.disabledPACK_ENVIRONMENT_DISABLEDintegrationRecords pack environment disabled.Active
pack.upgrade.proposedPACK_UPGRADE_PROPOSEDintegrationRecords pack upgrade proposed.Active
pack.upgrade.publishedPACK_UPGRADE_PUBLISHEDintegrationRecords pack upgrade published.Active
pack_source.createdPACK_SOURCE_CREATEDintegrationRecords pack source created.Active
pack_source.updatedPACK_SOURCE_UPDATEDintegrationRecords pack source updated.Active
pack_source.deletedPACK_SOURCE_DELETEDintegrationRecords pack source deleted.Active
pack_source.signature_policy_changedPACK_SOURCE_SIGNATURE_POLICY_CHANGEDauthorizationRecords pack source signature policy changed.Active
pack_source.sync_triggeredPACK_SOURCE_SYNC_TRIGGEREDintegrationRecords pack source sync triggered.Active
pack_source.sync_failedPACK_SOURCE_SYNC_FAILEDintegrationRecords pack source sync failed.Active
pack_source.unsigned_policy_usedPACK_SOURCE_UNSIGNED_POLICY_USEDauthorizationRecords pack source unsigned policy used.Active
environment.createWORKSPACE_ENVIRONMENT_CREATEDoperationsRecords environment create.Active
environment.updateWORKSPACE_ENVIRONMENT_UPDATEDoperationsRecords environment update.Active
environment.deleteWORKSPACE_ENVIRONMENT_DELETEDoperationsRecords environment delete.Active
SUBSCRIPTION_CREATEAUDIT_SUBSCRIPTION_CREATEgovernanceRecords subscription create.Active
audit.testAUDIT_TESTgovernanceRecords audit test.Active
audit.exportAUDIT_EXPORTgovernanceRecords audit export.Active
audit.retention.updatedAUDIT_RETENTION_UPDATEDgovernanceRecords audit retention updated.Active
audit.chain.checkpointAUDIT_CHAIN_CHECKPOINTgovernanceRecords audit chain checkpoint.Legacy read-only
audit.chain.verifyAUDIT_CHAIN_VERIFYgovernanceRecords audit chain verify.Active
dlp.policy.activatedDLP_POLICY_ACTIVATEDauthorizationRecords dlp policy activated.Active
dlp.policy.updatedDLP_POLICY_UPDATEDauthorizationRecords dlp policy updated.Active
dlp.policy.reviewedDLP_POLICY_REVIEWEDauthorizationRecords dlp policy reviewed.Active
dlp.policy.review_overdueDLP_POLICY_REVIEW_OVERDUEauthorizationRecords dlp policy review overdue.Active
dlp.scan.inputDLP_SCAN_INPUTsecurityRecords dlp scan input.Active
dlp.scan.outputDLP_SCAN_OUTPUTsecurityRecords dlp scan output.Active
dlp.violationDLP_VIOLATIONsecurityRecords dlp violation.Active
dlp.action_takenDLP_ACTION_TAKENsecurityRecords dlp action taken.Active
dlp.override.grantedDLP_OVERRIDE_GRANTEDauthorizationRecords dlp override granted.Active
dlp.override.rejectedDLP_OVERRIDE_REJECTEDsecurityRecords dlp override rejected.Active
dlp.classifier.degradedDLP_CLASSIFIER_DEGRADEDsecurityRecords dlp classifier degraded.Active
dlp.prompt_injection.detectedDLP_PROMPT_INJECTION_DETECTEDsecurityRecords dlp prompt injection detected.Active
dlp.hits.acknowledgedDLP_HITS_ACKNOWLEDGEDsecurityRecords dlp hits acknowledged.Active
dlp.exception.activatedDLP_EXCEPTION_ACTIVATEDsecurityRecords dlp exception activated.Active
dlp.exception.expiredDLP_EXCEPTION_EXPIREDsecurityRecords dlp exception expired.Active
dlp.pre_action.blockedDLP_PRE_ACTION_BLOCKEDsecurityRecords dlp pre action blocked.Active
company_context.ensuredCOMPANY_CONTEXT_ENSUREDdataRecords company context ensured.Active
company_context.page.createCOMPANY_CONTEXT_PAGE_CREATEdataRecords company context page create.Active
company_context.page.updateCOMPANY_CONTEXT_PAGE_UPDATEdataRecords company context page update.Active
company_context.page.deleteCOMPANY_CONTEXT_PAGE_DELETEdataRecords company context page delete.Active
company_context.page.reclassifyCOMPANY_CONTEXT_PAGE_RECLASSIFYdataRecords company context page reclassify.Active
company_context.source.ingestCOMPANY_CONTEXT_SOURCE_INGESTdataRecords company context source ingest.Active
company_context.source.retryCOMPANY_CONTEXT_SOURCE_RETRYdataRecords company context source retry.Active
company_context.source.bulk-deleteCOMPANY_CONTEXT_SOURCE_BULK_DELETEdataRecords company context source bulk delete.Active
company_context.folder.deleteCOMPANY_CONTEXT_FOLDER_DELETEdataRecords company context folder delete.Active
moderation.policy.updatedMODERATION_POLICY_UPDATEDauthorizationRecords moderation policy updated.Active
moderation.policy.hitMODERATION_POLICY_HITauthorizationRecords moderation policy hit.Active
classification.scheme_updatedCLASSIFICATION_SCHEME_UPDATEDgovernanceRecords classification scheme updated.Active
classification.document_labelledCLASSIFICATION_DOCUMENT_LABELLEDdataRecords classification document labelled.Active
classification.endpoint_ratedCLASSIFICATION_ENDPOINT_RATEDgovernanceRecords classification endpoint rated.Active
classification.aggregation_cappedCLASSIFICATION_AGGREGATION_CAPPEDgovernanceRecords classification aggregation capped.Active
security.clearance_grantedCLEARANCE_GRANTEDauthorizationRecords security clearance granted.Active
security.clearance_override_createdCLEARANCE_OVERRIDE_CREATEDauthorizationRecords security clearance override created.Active
security.clearance_baseline_setCLEARANCE_BASELINE_SETauthorizationRecords security clearance baseline set.Active
security.clearance_revokedCLEARANCE_REVOKEDauthorizationRecords security clearance revoked.Active
security.sessions_terminatedSESSIONS_TERMINATEDauthenticationRecords security sessions terminated.Active
security.spillage_detectedSPILLAGE_DETECTEDsecurityRecords security spillage detected.Active
security.clearance_egress_blockedCLEARANCE_EGRESS_BLOCKEDauthorizationRecords security clearance egress blocked.Active
impersonation.session.createdIMPERSONATION_SESSION_CREATEDauthenticationRecords impersonation session created.Active
scim.user.provisionedSCIM_USER_PROVISIONEDsecurityRecords scim user provisioned.Active
scim.user.updatedSCIM_USER_UPDATEDsecurityRecords scim user updated.Active
scim.user.deactivatedSCIM_USER_DEACTIVATEDsecurityRecords scim user deactivated.Active
scim.user.reactivatedSCIM_USER_REACTIVATEDsecurityRecords scim user reactivated.Active
scim.user.linkedSCIM_USER_LINKEDsecurityRecords scim user linked.Active
scim.group.createdSCIM_GROUP_CREATEDsecurityRecords scim group created.Active
scim.group.updatedSCIM_GROUP_UPDATEDsecurityRecords scim group updated.Active
scim.group.deletedSCIM_GROUP_DELETEDsecurityRecords scim group deleted.Active
scim.group.member_addedSCIM_GROUP_MEMBER_ADDEDsecurityRecords scim group member added.Active
scim.group.member_removedSCIM_GROUP_MEMBER_REMOVEDsecurityRecords scim group member removed.Active
scim.token.generatedSCIM_TOKEN_GENERATEDsecurityRecords scim token generated.Active
scim.token.revokedSCIM_TOKEN_REVOKEDsecurityRecords scim token revoked.Active
table.createTABLE_CREATEdataRecords table create.Active
table.updateTABLE_UPDATEdataRecords table update.Active
table.deleteTABLE_DELETEdataRecords table delete.Active
table.archiveTABLE_ARCHIVEdataRecords table archive.Active
table.restoreTABLE_RESTOREdataRecords table restore.Active
table.writeTABLE_WRITEdataRecords table write.Active
table.external_commit_reconciledTABLE_EXTERNAL_COMMIT_RECONCILEDdataRecords table external commit reconciled.Active
table.maintenance_snapshots_expiredTABLE_MAINTENANCE_SNAPSHOTS_EXPIREDdataRecords table maintenance snapshots expired.Active
table.maintenance_completedTABLE_MAINTENANCE_COMPLETEDdataRecords table maintenance completed.Active
table.orphan_reclaimedTABLE_ORPHAN_RECLAIMEDdataRecords table orphan reclaimed.Active
table.warehouse_drift_detectedTABLE_WAREHOUSE_DRIFT_DETECTEDdataRecords table warehouse drift detected.Active
table.warehouse_profile_reconciledTABLE_WAREHOUSE_PROFILE_RECONCILEDdataRecords table warehouse profile reconciled.Active
table.orphan_detectedTABLE_ORPHAN_DETECTEDdataRecords table orphan detected.Active
table.cutover_startedTABLE_CUTOVER_STARTEDdataRecords table cutover started.Active
table.cutover_completedTABLE_CUTOVER_COMPLETEDdataRecords table cutover completed.Active
table.cutover_failedTABLE_CUTOVER_FAILEDdataRecords table cutover failed.Active
policy.compilePOLICY_COMPILEauthorizationRecords policy compile.Active
data_source.appliedDATA_SOURCE_APPLIEDdataRecords data source applied.Active
data-source.resolve-conflictDATA_SOURCE_RESOLVE_CONFLICTdataRecords data source resolve conflict.Active
data-source.removeDATA_SOURCE_REMOVEdataRecords data source remove.Active
policy.createPOLICY_CREATEauthorizationRecords policy create.Active
policy.updatePOLICY_UPDATEauthorizationRecords policy update.Active
policy.deletePOLICY_DELETEauthorizationRecords policy delete.Active
iceberg.configICEBERG_CONFIGdataRecords iceberg config.Active
iceberg.catalogICEBERG_CATALOGdataRecords iceberg catalog.Active
egress.blockedEGRESS_BLOCKEDsecurityRecords egress blocked.Active
egress.allowedEGRESS_ALLOWEDsecurityRecords egress allowed.Active
integration.connection.createdINTEGRATION_CONNECTION_CREATEDintegrationRecords integration connection created.Active
integration.connection.updatedINTEGRATION_CONNECTION_UPDATEDintegrationRecords integration connection updated.Active
integration.connection.deletedINTEGRATION_CONNECTION_DELETEDintegrationRecords integration connection deleted.Active
chat.admin.accessCHAT_ADMIN_ACCESSoperationsRecords chat admin access.Active
chat.message.truncatedCHAT_MESSAGE_TRUNCATEDoperationsRecords chat message truncated.Active
chat.history.searchCHAT_HISTORY_SEARCHoperationsRecords chat history search.Active
chat.conversation.archivedCHAT_CONVERSATION_ARCHIVEDoperationsRecords chat conversation archived.Active
chat.conversation.deletedCHAT_CONVERSATION_DELETEDoperationsRecords chat conversation deleted.Active
chat.conversation.createdCHAT_CONVERSATION_CREATEDoperationsRecords chat conversation created.Active
chat.message.sentCHAT_MESSAGE_SENToperationsRecords chat message sent.Active
chat.message.receivedCHAT_MESSAGE_RECEIVEDoperationsRecords chat message received.Active
chat.message.abortedCHAT_MESSAGE_ABORTEDoperationsRecords chat message aborted.Active
cortex.plan.builtCORTEX_PLAN_BUILToperationsRecords cortex plan built.Active
cortex.plan.failedCORTEX_PLAN_FAILEDoperationsRecords cortex plan failed.Active
cortex.plan.messageCORTEX_PLAN_MESSAGEoperationsRecords cortex plan message.Active
SIGNIN_FAILEDSIGNIN_FAILEDauthenticationRecords signin failed.Active
SIGNIN_RATE_LIMITEDSIGNIN_RATE_LIMITEDauthenticationRecords signin rate limited.Active
2FA_FAILEDTWO_FACTOR_FAILEDoperationsRecords 2fa failed.Active
SESSION_CREATESESSION_CREATEauthenticationRecords session create.Active
SESSION_REVOKESESSION_REVOKEauthenticationRecords session revoke.Active
super_admin.role.grantedSUPER_ADMIN_ROLE_GRANTEDauthorizationRecords super admin role granted.Active
super_admin.org_membership.grantedSUPER_ADMIN_ORG_MEMBERSHIP_GRANTEDauthorizationRecords super admin org membership granted.Active
super_admin.org_membership.elevatedSUPER_ADMIN_ORG_MEMBERSHIP_ELEVATEDsecurityRecords super admin org membership elevated.Active
service_account.credential.connectedSERVICE_ACCOUNT_CREDENTIAL_CONNECTEDoperationsRecords service account credential connected.Active
service_account.credential.disconnectedSERVICE_ACCOUNT_CREDENTIAL_DISCONNECTEDoperationsRecords service account credential disconnected.Active

Audit resource types

Resource typeRegistry keyDescription
secretSECRETAudit subject representing secret.
secretProviderSECRET_PROVIDERAudit subject representing secret provider.
userUSERAudit subject representing user.
organizationORGANIZATIONAudit subject representing organization.
organizationMemberORGANIZATION_MEMBERAudit subject representing organization member.
workspaceWORKSPACEAudit subject representing workspace.
workspaceEnvironmentWORKSPACE_ENVIRONMENTAudit subject representing workspace environment.
fileFILEAudit subject representing file.
workflowWORKFLOWAudit subject representing workflow.
knowledgeBaseKNOWLEDGE_BASEAudit subject representing knowledge base.
kb_pageKB_PAGEAudit subject representing kb page.
documentDOCUMENTAudit subject representing document.
folderFOLDERAudit subject representing folder.
templateTEMPLATEAudit subject representing template.
processFlowPROCESS_FLOWAudit subject representing process flow.
processTemplateprocess_flowAudit subject representing process template.
scheduleSCHEDULEAudit subject representing schedule.
memoryMEMORYAudit subject representing memory.
chatCHATAudit subject representing chat.
webhookWEBHOOKAudit subject representing webhook.
copilotToolCOPILOT_TOOLAudit subject representing copilot tool.
integrationINTEGRATIONAudit subject representing integration.
integrationEntitlementINTEGRATION_ENTITLEMENTAudit subject representing integration entitlement.
mcpServerMCP_SERVERAudit subject representing mcp server.
a2aAgentA2A_AGENTAudit subject representing a2a agent.
a2aTaskA2A_TASKAudit subject representing a2a task.
a2aPushConfigA2A_PUSH_CONFIGAudit subject representing a2a push config.
pack_sourcePACK_SOURCEAudit subject representing pack source.
eventLogReceiverAUDIT_LOG_SUBSCRIPTIONAudit subject representing event log receiver.
eventLogAUDIT_LOGAudit subject representing event log.
eventLogRetentionConfigAUDIT_LOG_RETENTION_CONFIGAudit subject representing event log retention config.
auditChainAUDIT_CHAINAudit subject representing audit chain.
sessionSESSIONAudit subject representing session.
userClearanceUSER_CLEARANCEAudit subject representing user clearance.
organizationPolicyORGANIZATION_POLICYAudit subject representing organization policy.
integration_connectionINTEGRATION_CONNECTIONAudit subject representing integration connection.
dlpHitsDLP_HITSAudit subject representing dlp hits.
organizationIntegrationAccountORGANIZATION_INTEGRATION_ACCOUNTAudit subject representing organization integration account.
dlpPolicyDLP_POLICYAudit subject representing dlp policy.
moderationPolicyMODERATION_POLICYAudit subject representing moderation policy.
UserSCIM_USERAudit subject representing user.
GroupSCIM_GROUPAudit subject representing group.
TokenSCIM_TOKENAudit subject representing token.
sandbox-egressSANDBOX_EGRESSAudit subject representing sandbox egress.
managed_tableMANAGED_TABLEAudit subject representing managed table.
managed-tableMANAGED_TABLE_HYPHENATEDAudit subject representing managed table.
policy-bundlePOLICY_BUNDLEAudit subject representing policy bundle.
data_sourceDATA_SOURCEAudit subject representing data source.
data-sourceDATA_SOURCE_HYPHENATEDAudit subject representing data source.
data-access-policyDATA_ACCESS_POLICYAudit subject representing data access policy.
iceberg_catalogICEBERG_CATALOGAudit subject representing iceberg catalog.
chat_conversationCHAT_CONVERSATIONAudit subject representing chat conversation.
chat_message_embeddingCHAT_MESSAGE_EMBEDDINGAudit subject representing chat message embedding.
chat_messageCHAT_MESSAGEAudit subject representing chat message.
workflow_planWORKFLOW_PLANAudit subject representing workflow plan.
packInstallPACK_INSTALLAudit subject representing pack install.
policyExecutionGrantPOLICY_EXECUTION_GRANTAudit subject representing policy execution grant.
authorizationContextAUTHORIZATION_CONTEXTAudit subject representing authorization context.
objectTypeOBJECT_TYPEAudit subject representing object type.
linkTypeLINK_TYPEAudit subject representing link type.
actionTypeACTION_TYPEAudit subject representing action type.
objectInstanceOBJECT_INSTANCEAudit subject representing object instance.
linkInstanceLINK_INSTANCEAudit subject representing link instance.
ontologyEffectONTOLOGY_EFFECTAudit subject representing ontology effect.
ontologyBranchONTOLOGY_BRANCHAudit subject representing ontology branch.
packCatalogPACK_CATALOGAudit subject representing pack catalog.
serviceAccountCredentialSERVICE_ACCOUNT_CREDENTIALAudit subject representing service account credential.

Workflow lifecycle events

ActionRegistry key
workflow.scheduledSCHEDULED
workflow.startedSTARTED
workflow.pausedPAUSED
workflow.resumedRESUMED
workflow.completedCOMPLETED
workflow.failedFAILED
workflow.terminatedTERMINATED
workflow.cancelledCANCELLED
workflow.purgedPURGED

Workflow resources: workflowworkflow-executionworkflow-schedule

Integrity events

ActionRegistry key
integrity.event-log.verification-failedAUDIT_LOG_VERIFICATION_FAILED
integrity.event-log.checkpoint-failedAUDIT_LOG_CHECKPOINT_FAILED
integrity.dapr-history.verification-failedDAPR_HISTORY_VERIFICATION_FAILED
integrity.dapr-history.configuration-mismatchDAPR_SIGNING_CONFIGURATION_MISMATCH
integrity.incident.acknowledgedINCIDENT_ACKNOWLEDGED
integrity.incident.recoveredINCIDENT_RECOVERED

Integrity resources: event-log-chainevent-log-checkpointdapr-workflow-historyintegrity-incident

Classified events

Audit list, filtered-list, and NDJSON export apply the same clearance rule. If an event is classified above the viewer's rank, or uses a different classification scheme, Scrydon returns the action, actor, organization, timestamp, decision evidence, and integrity-chain fields while replacing the resource ID and sensitive request context with null. The row includes redacted: true, and the Audit Log displays a lock. Select a row in the Audit Log to inspect its event, actor/resource, policy/classification, request, metadata, and chain-integrity evidence. The detail panel preserves the same clearance redaction as the list response.

Organizations without user-clearance records keep the previous visibility behavior. Historical rows are not reclassified.

Integrity

New events participate in a mandatory SHA-256 chain for their organization or global security scope. Signed ML-DSA-65 checkpoints can be verified from the Audit Log settings page or through the verification API. Recent valid rows can temporarily report “awaiting a checkpoint”; historical rows created before the cutover are explicitly reported outside the cryptographic proof. There is no configuration switch that disables chain integrity.

Authorization decision evidence is always complete by policy; there is no runtime logging tier. A degraded local enqueue raises an alert and can be reconciled only with the exact original decision ID and payload.

On this page

On this page