Audit Log catalogue
The complete set of audit, workflow, and integrity events recorded by Scrydon.
Scrydon accepts only actions and resource types in this catalogue. The page is rendered from the same registry used by server validation, so an event value cannot be accepted without appearing here.
See Audit logging for retention, export, Log Receiver forwarding, and the common envelope carried by every event type.
Audit actions
Authorization entries cover every combination of action (read, write,
delete, execute, admin, retire) and outcome (GRANTED, DENIED,
INDETERMINATE). One decision produces one entry. The evaluated subject is
stored in the bounded decision evidence, while producer identifies the
authenticated Scrydon workload that submitted it.
| Action | Registry key | Family | Description | Status |
|---|---|---|---|---|
SECRET_CREATE | SECRET_CREATE | integration | Records secret create. | Active |
SECRET_UPDATE | SECRET_UPDATE | integration | Records secret update. | Active |
SECRET_DELETE | SECRET_DELETE | integration | Records secret delete. | Active |
SECRET_ACCESS | SECRET_ACCESS | integration | Records secret access. | Active |
PROVIDER_CREATE | PROVIDER_CREATE | integration | Records provider create. | Active |
PROVIDER_UPDATE | PROVIDER_UPDATE | integration | Records provider update. | Active |
PROVIDER_DELETE | PROVIDER_DELETE | integration | Records provider delete. | Active |
PROVIDER_TEST | PROVIDER_TEST | integration | Records provider test. | Active |
RESOURCE_CREATE | RESOURCE_CREATE | data | Records resource create. | Active |
RESOURCE_UPDATE | RESOURCE_UPDATE | data | Records resource update. | Active |
RESOURCE_DELETE | RESOURCE_DELETE | data | Records resource delete. | Active |
RESOURCE_ACCESS | RESOURCE_ACCESS | data | Records resource access. | Active |
ontology.entity.changed | ONTOLOGY_ENTITY_CHANGED | operations | Records ontology entity changed. | Active |
ontology.effect.requested | ONTOLOGY_EFFECT_REQUESTED | operations | Records ontology effect requested. | Active |
AUTH_READ_DENIED | AUTH_READ_DENIED | authorization | Records auth read denied. | Active |
AUTH_WRITE_DENIED | AUTH_WRITE_DENIED | authorization | Records auth write denied. | Active |
AUTH_DELETE_DENIED | AUTH_DELETE_DENIED | authorization | Records auth delete denied. | Active |
AUTH_EXECUTE_DENIED | AUTH_EXECUTE_DENIED | authorization | Records auth execute denied. | Active |
AUTH_ADMIN_DENIED | AUTH_ADMIN_DENIED | authorization | Records auth admin denied. | Active |
AUTH_RETIRE_DENIED | AUTH_RETIRE_DENIED | authorization | Records auth retire denied. | Active |
AUTH_READ_GRANTED | AUTH_READ_GRANTED | authorization | Records auth read granted. | Active |
AUTH_WRITE_GRANTED | AUTH_WRITE_GRANTED | authorization | Records auth write granted. | Active |
AUTH_DELETE_GRANTED | AUTH_DELETE_GRANTED | authorization | Records auth delete granted. | Active |
AUTH_EXECUTE_GRANTED | AUTH_EXECUTE_GRANTED | authorization | Records auth execute granted. | Active |
AUTH_ADMIN_GRANTED | AUTH_ADMIN_GRANTED | authorization | Records auth admin granted. | Active |
AUTH_RETIRE_GRANTED | AUTH_RETIRE_GRANTED | authorization | Records auth retire granted. | Active |
AUTH_READ_INDETERMINATE | AUTH_READ_INDETERMINATE | authorization | Records auth read indeterminate. | Active |
AUTH_WRITE_INDETERMINATE | AUTH_WRITE_INDETERMINATE | authorization | Records auth write indeterminate. | Active |
AUTH_DELETE_INDETERMINATE | AUTH_DELETE_INDETERMINATE | authorization | Records auth delete indeterminate. | Active |
AUTH_EXECUTE_INDETERMINATE | AUTH_EXECUTE_INDETERMINATE | authorization | Records auth execute indeterminate. | Active |
AUTH_ADMIN_INDETERMINATE | AUTH_ADMIN_INDETERMINATE | authorization | Records auth admin indeterminate. | Active |
AUTH_RETIRE_INDETERMINATE | AUTH_RETIRE_INDETERMINATE | authorization | Records auth retire indeterminate. | Active |
EXECUTION_GRANT_CREATED | EXECUTION_GRANT_CREATED | authorization | Records execution grant created. | Active |
EXECUTION_GRANT_REJECTED | EXECUTION_GRANT_REJECTED | authorization | Records execution grant rejected. | Active |
EXECUTION_GRANT_BOUND | EXECUTION_GRANT_BOUND | authorization | Records execution grant bound. | Active |
EXECUTION_GRANT_DERIVED | EXECUTION_GRANT_DERIVED | authorization | Records execution grant derived. | Active |
EXECUTION_GRANT_VALIDATED | EXECUTION_GRANT_VALIDATED | authorization | Records execution grant validated. | Active |
EXECUTION_GRANT_REVOKED | EXECUTION_GRANT_REVOKED | authorization | Records execution grant revoked. | Active |
EXECUTION_GRANT_EXPIRED | EXECUTION_GRANT_EXPIRED | authorization | Records execution grant expired. | Active |
AUTHORIZATION_CONTEXT_CREATED | AUTHORIZATION_CONTEXT_CREATED | operations | Records authorization context created. | Active |
AUTHORIZATION_CONTEXT_REAUTHORIZED | AUTHORIZATION_CONTEXT_REAUTHORIZED | operations | Records authorization context reauthorized. | Active |
AUTHORIZATION_CONTEXT_RESOLVED | AUTHORIZATION_CONTEXT_RESOLVED | operations | Records authorization context resolved. | Active |
AUTHORIZATION_CONTEXT_REJECTED | AUTHORIZATION_CONTEXT_REJECTED | operations | Records authorization context rejected. | Active |
AUTHORIZATION_CONTEXT_REVOKED | AUTHORIZATION_CONTEXT_REVOKED | operations | Records authorization context revoked. | Active |
AUTHORIZATION_CONTEXT_EXPIRED | AUTHORIZATION_CONTEXT_EXPIRED | operations | Records authorization context expired. | Active |
authz.audit.policy.updated | AUTHZ_AUDIT_POLICY_UPDATED | authorization | Records authz audit policy updated. | Legacy read-only |
isolation.policy.updated | ISOLATION_POLICY_UPDATED | authorization | Records isolation policy updated. | Active |
AGENT_EXECUTION_ISOLATION_RELAXED | AGENT_EXECUTION_ISOLATION_RELAXED | operations | Records agent execution isolation relaxed. | Active |
INTEGRATION_ENTITLEMENT_MODE_CHANGE | INTEGRATION_ENTITLEMENT_MODE_CHANGE | authorization | Records integration entitlement mode change. | Active |
INTEGRATION_ENTITLEMENT_GRANT | INTEGRATION_ENTITLEMENT_GRANT | authorization | Records integration entitlement grant. | Active |
INTEGRATION_ENTITLEMENT_REVOKE | INTEGRATION_ENTITLEMENT_REVOKE | authorization | Records integration entitlement revoke. | Active |
INTEGRATION_ENTITLEMENT_UPDATE | INTEGRATION_ENTITLEMENT_UPDATE | authorization | Records integration entitlement update. | Active |
INTEGRATION_ACCESS_DENIED | INTEGRATION_ACCESS_DENIED | integration | Records integration access denied. | Active |
INTEGRATION_CREDENTIAL_RESOLVED | INTEGRATION_CREDENTIAL_RESOLVED | integration | Records integration credential resolved. | Active |
INTEGRATION_UPGRADED | INTEGRATION_UPGRADED | integration | Records integration upgraded. | Active |
INTEGRATION_ROLLED_BACK | INTEGRATION_ROLLED_BACK | integration | Records integration rolled back. | Active |
INTEGRATION_ENABLE | INTEGRATION_ENABLE | integration | Records integration enable. | Active |
INTEGRATION_DISABLE | INTEGRATION_DISABLE | integration | Records integration disable. | Active |
INTEGRATION_DEPRECATE | INTEGRATION_DEPRECATE | integration | Records integration deprecate. | Active |
INTEGRATION_CANCEL_DEPRECATION | INTEGRATION_CANCEL_DEPRECATION | integration | Records integration cancel deprecation. | Active |
integration.execution.started | INTEGRATION_EXECUTION_STARTED | integration | Records integration execution started. | Active |
integration.execution.succeeded | INTEGRATION_EXECUTION_SUCCEEDED | integration | Records integration execution succeeded. | Active |
integration.execution.failed | INTEGRATION_EXECUTION_FAILED | integration | Records integration execution failed. | Active |
MCP_TOOL_EXECUTED | MCP_TOOL_EXECUTED | integration | Records mcp tool executed. | Active |
MCP_SERVER_AVAILABILITY_CHANGED | MCP_SERVER_AVAILABILITY_CHANGED | integration | Records mcp server availability changed. | Active |
a2a.publication.created | A2A_PUBLICATION_CREATED | operations | Records a2a publication created. | Active |
a2a.publication.updated | A2A_PUBLICATION_UPDATED | operations | Records a2a publication updated. | Active |
a2a.publication.republished | A2A_PUBLICATION_REPUBLISHED | operations | Records a2a publication republished. | Active |
a2a.publication.unpublished | A2A_PUBLICATION_UNPUBLISHED | operations | Records a2a publication unpublished. | Active |
a2a.task.created | A2A_TASK_CREATED | operations | Records a2a task created. | Active |
a2a.task.canceled | A2A_TASK_CANCELED | operations | Records a2a task canceled. | Active |
a2a.push_config.created | A2A_PUSH_CONFIG_CREATED | operations | Records a2a push config created. | Active |
a2a.push_config.deleted | A2A_PUSH_CONFIG_DELETED | operations | Records a2a push config deleted. | Active |
a2a.push_delivery.dead_lettered | A2A_PUSH_DELIVERY_DEAD_LETTERED | operations | Records a2a push delivery dead lettered. | Active |
pack.catalog.uploaded | PACK_CATALOG_UPLOADED | integration | Records pack catalog uploaded. | Active |
pack.catalog.retired | PACK_CATALOG_RETIRED | integration | Records pack catalog retired. | Active |
pack.environment.enabled | PACK_ENVIRONMENT_ENABLED | integration | Records pack environment enabled. | Active |
pack.environment.disabled | PACK_ENVIRONMENT_DISABLED | integration | Records pack environment disabled. | Active |
pack.upgrade.proposed | PACK_UPGRADE_PROPOSED | integration | Records pack upgrade proposed. | Active |
pack.upgrade.published | PACK_UPGRADE_PUBLISHED | integration | Records pack upgrade published. | Active |
pack_source.created | PACK_SOURCE_CREATED | integration | Records pack source created. | Active |
pack_source.updated | PACK_SOURCE_UPDATED | integration | Records pack source updated. | Active |
pack_source.deleted | PACK_SOURCE_DELETED | integration | Records pack source deleted. | Active |
pack_source.signature_policy_changed | PACK_SOURCE_SIGNATURE_POLICY_CHANGED | authorization | Records pack source signature policy changed. | Active |
pack_source.sync_triggered | PACK_SOURCE_SYNC_TRIGGERED | integration | Records pack source sync triggered. | Active |
pack_source.sync_failed | PACK_SOURCE_SYNC_FAILED | integration | Records pack source sync failed. | Active |
pack_source.unsigned_policy_used | PACK_SOURCE_UNSIGNED_POLICY_USED | authorization | Records pack source unsigned policy used. | Active |
environment.create | WORKSPACE_ENVIRONMENT_CREATED | operations | Records environment create. | Active |
environment.update | WORKSPACE_ENVIRONMENT_UPDATED | operations | Records environment update. | Active |
environment.delete | WORKSPACE_ENVIRONMENT_DELETED | operations | Records environment delete. | Active |
SUBSCRIPTION_CREATE | AUDIT_SUBSCRIPTION_CREATE | governance | Records subscription create. | Active |
audit.test | AUDIT_TEST | governance | Records audit test. | Active |
audit.export | AUDIT_EXPORT | governance | Records audit export. | Active |
audit.retention.updated | AUDIT_RETENTION_UPDATED | governance | Records audit retention updated. | Active |
audit.chain.checkpoint | AUDIT_CHAIN_CHECKPOINT | governance | Records audit chain checkpoint. | Legacy read-only |
audit.chain.verify | AUDIT_CHAIN_VERIFY | governance | Records audit chain verify. | Active |
dlp.policy.activated | DLP_POLICY_ACTIVATED | authorization | Records dlp policy activated. | Active |
dlp.policy.updated | DLP_POLICY_UPDATED | authorization | Records dlp policy updated. | Active |
dlp.policy.reviewed | DLP_POLICY_REVIEWED | authorization | Records dlp policy reviewed. | Active |
dlp.policy.review_overdue | DLP_POLICY_REVIEW_OVERDUE | authorization | Records dlp policy review overdue. | Active |
dlp.scan.input | DLP_SCAN_INPUT | security | Records dlp scan input. | Active |
dlp.scan.output | DLP_SCAN_OUTPUT | security | Records dlp scan output. | Active |
dlp.violation | DLP_VIOLATION | security | Records dlp violation. | Active |
dlp.action_taken | DLP_ACTION_TAKEN | security | Records dlp action taken. | Active |
dlp.override.granted | DLP_OVERRIDE_GRANTED | authorization | Records dlp override granted. | Active |
dlp.override.rejected | DLP_OVERRIDE_REJECTED | security | Records dlp override rejected. | Active |
dlp.classifier.degraded | DLP_CLASSIFIER_DEGRADED | security | Records dlp classifier degraded. | Active |
dlp.prompt_injection.detected | DLP_PROMPT_INJECTION_DETECTED | security | Records dlp prompt injection detected. | Active |
dlp.hits.acknowledged | DLP_HITS_ACKNOWLEDGED | security | Records dlp hits acknowledged. | Active |
dlp.exception.activated | DLP_EXCEPTION_ACTIVATED | security | Records dlp exception activated. | Active |
dlp.exception.expired | DLP_EXCEPTION_EXPIRED | security | Records dlp exception expired. | Active |
dlp.pre_action.blocked | DLP_PRE_ACTION_BLOCKED | security | Records dlp pre action blocked. | Active |
company_context.ensured | COMPANY_CONTEXT_ENSURED | data | Records company context ensured. | Active |
company_context.page.create | COMPANY_CONTEXT_PAGE_CREATE | data | Records company context page create. | Active |
company_context.page.update | COMPANY_CONTEXT_PAGE_UPDATE | data | Records company context page update. | Active |
company_context.page.delete | COMPANY_CONTEXT_PAGE_DELETE | data | Records company context page delete. | Active |
company_context.page.reclassify | COMPANY_CONTEXT_PAGE_RECLASSIFY | data | Records company context page reclassify. | Active |
company_context.source.ingest | COMPANY_CONTEXT_SOURCE_INGEST | data | Records company context source ingest. | Active |
company_context.source.retry | COMPANY_CONTEXT_SOURCE_RETRY | data | Records company context source retry. | Active |
company_context.source.bulk-delete | COMPANY_CONTEXT_SOURCE_BULK_DELETE | data | Records company context source bulk delete. | Active |
company_context.folder.delete | COMPANY_CONTEXT_FOLDER_DELETE | data | Records company context folder delete. | Active |
moderation.policy.updated | MODERATION_POLICY_UPDATED | authorization | Records moderation policy updated. | Active |
moderation.policy.hit | MODERATION_POLICY_HIT | authorization | Records moderation policy hit. | Active |
classification.scheme_updated | CLASSIFICATION_SCHEME_UPDATED | governance | Records classification scheme updated. | Active |
classification.document_labelled | CLASSIFICATION_DOCUMENT_LABELLED | data | Records classification document labelled. | Active |
classification.endpoint_rated | CLASSIFICATION_ENDPOINT_RATED | governance | Records classification endpoint rated. | Active |
classification.aggregation_capped | CLASSIFICATION_AGGREGATION_CAPPED | governance | Records classification aggregation capped. | Active |
security.clearance_granted | CLEARANCE_GRANTED | authorization | Records security clearance granted. | Active |
security.clearance_override_created | CLEARANCE_OVERRIDE_CREATED | authorization | Records security clearance override created. | Active |
security.clearance_baseline_set | CLEARANCE_BASELINE_SET | authorization | Records security clearance baseline set. | Active |
security.clearance_revoked | CLEARANCE_REVOKED | authorization | Records security clearance revoked. | Active |
security.sessions_terminated | SESSIONS_TERMINATED | authentication | Records security sessions terminated. | Active |
security.spillage_detected | SPILLAGE_DETECTED | security | Records security spillage detected. | Active |
security.clearance_egress_blocked | CLEARANCE_EGRESS_BLOCKED | authorization | Records security clearance egress blocked. | Active |
impersonation.session.created | IMPERSONATION_SESSION_CREATED | authentication | Records impersonation session created. | Active |
scim.user.provisioned | SCIM_USER_PROVISIONED | security | Records scim user provisioned. | Active |
scim.user.updated | SCIM_USER_UPDATED | security | Records scim user updated. | Active |
scim.user.deactivated | SCIM_USER_DEACTIVATED | security | Records scim user deactivated. | Active |
scim.user.reactivated | SCIM_USER_REACTIVATED | security | Records scim user reactivated. | Active |
scim.user.linked | SCIM_USER_LINKED | security | Records scim user linked. | Active |
scim.group.created | SCIM_GROUP_CREATED | security | Records scim group created. | Active |
scim.group.updated | SCIM_GROUP_UPDATED | security | Records scim group updated. | Active |
scim.group.deleted | SCIM_GROUP_DELETED | security | Records scim group deleted. | Active |
scim.group.member_added | SCIM_GROUP_MEMBER_ADDED | security | Records scim group member added. | Active |
scim.group.member_removed | SCIM_GROUP_MEMBER_REMOVED | security | Records scim group member removed. | Active |
scim.token.generated | SCIM_TOKEN_GENERATED | security | Records scim token generated. | Active |
scim.token.revoked | SCIM_TOKEN_REVOKED | security | Records scim token revoked. | Active |
table.create | TABLE_CREATE | data | Records table create. | Active |
table.update | TABLE_UPDATE | data | Records table update. | Active |
table.delete | TABLE_DELETE | data | Records table delete. | Active |
table.archive | TABLE_ARCHIVE | data | Records table archive. | Active |
table.restore | TABLE_RESTORE | data | Records table restore. | Active |
table.write | TABLE_WRITE | data | Records table write. | Active |
table.external_commit_reconciled | TABLE_EXTERNAL_COMMIT_RECONCILED | data | Records table external commit reconciled. | Active |
table.maintenance_snapshots_expired | TABLE_MAINTENANCE_SNAPSHOTS_EXPIRED | data | Records table maintenance snapshots expired. | Active |
table.maintenance_completed | TABLE_MAINTENANCE_COMPLETED | data | Records table maintenance completed. | Active |
table.orphan_reclaimed | TABLE_ORPHAN_RECLAIMED | data | Records table orphan reclaimed. | Active |
table.warehouse_drift_detected | TABLE_WAREHOUSE_DRIFT_DETECTED | data | Records table warehouse drift detected. | Active |
table.warehouse_profile_reconciled | TABLE_WAREHOUSE_PROFILE_RECONCILED | data | Records table warehouse profile reconciled. | Active |
table.orphan_detected | TABLE_ORPHAN_DETECTED | data | Records table orphan detected. | Active |
table.cutover_started | TABLE_CUTOVER_STARTED | data | Records table cutover started. | Active |
table.cutover_completed | TABLE_CUTOVER_COMPLETED | data | Records table cutover completed. | Active |
table.cutover_failed | TABLE_CUTOVER_FAILED | data | Records table cutover failed. | Active |
policy.compile | POLICY_COMPILE | authorization | Records policy compile. | Active |
data_source.applied | DATA_SOURCE_APPLIED | data | Records data source applied. | Active |
data-source.resolve-conflict | DATA_SOURCE_RESOLVE_CONFLICT | data | Records data source resolve conflict. | Active |
data-source.remove | DATA_SOURCE_REMOVE | data | Records data source remove. | Active |
policy.create | POLICY_CREATE | authorization | Records policy create. | Active |
policy.update | POLICY_UPDATE | authorization | Records policy update. | Active |
policy.delete | POLICY_DELETE | authorization | Records policy delete. | Active |
iceberg.config | ICEBERG_CONFIG | data | Records iceberg config. | Active |
iceberg.catalog | ICEBERG_CATALOG | data | Records iceberg catalog. | Active |
egress.blocked | EGRESS_BLOCKED | security | Records egress blocked. | Active |
egress.allowed | EGRESS_ALLOWED | security | Records egress allowed. | Active |
integration.connection.created | INTEGRATION_CONNECTION_CREATED | integration | Records integration connection created. | Active |
integration.connection.updated | INTEGRATION_CONNECTION_UPDATED | integration | Records integration connection updated. | Active |
integration.connection.deleted | INTEGRATION_CONNECTION_DELETED | integration | Records integration connection deleted. | Active |
chat.admin.access | CHAT_ADMIN_ACCESS | operations | Records chat admin access. | Active |
chat.message.truncated | CHAT_MESSAGE_TRUNCATED | operations | Records chat message truncated. | Active |
chat.history.search | CHAT_HISTORY_SEARCH | operations | Records chat history search. | Active |
chat.conversation.archived | CHAT_CONVERSATION_ARCHIVED | operations | Records chat conversation archived. | Active |
chat.conversation.deleted | CHAT_CONVERSATION_DELETED | operations | Records chat conversation deleted. | Active |
chat.conversation.created | CHAT_CONVERSATION_CREATED | operations | Records chat conversation created. | Active |
chat.message.sent | CHAT_MESSAGE_SENT | operations | Records chat message sent. | Active |
chat.message.received | CHAT_MESSAGE_RECEIVED | operations | Records chat message received. | Active |
chat.message.aborted | CHAT_MESSAGE_ABORTED | operations | Records chat message aborted. | Active |
cortex.plan.built | CORTEX_PLAN_BUILT | operations | Records cortex plan built. | Active |
cortex.plan.failed | CORTEX_PLAN_FAILED | operations | Records cortex plan failed. | Active |
cortex.plan.message | CORTEX_PLAN_MESSAGE | operations | Records cortex plan message. | Active |
SIGNIN_FAILED | SIGNIN_FAILED | authentication | Records signin failed. | Active |
SIGNIN_RATE_LIMITED | SIGNIN_RATE_LIMITED | authentication | Records signin rate limited. | Active |
2FA_FAILED | TWO_FACTOR_FAILED | operations | Records 2fa failed. | Active |
SESSION_CREATE | SESSION_CREATE | authentication | Records session create. | Active |
SESSION_REVOKE | SESSION_REVOKE | authentication | Records session revoke. | Active |
super_admin.role.granted | SUPER_ADMIN_ROLE_GRANTED | authorization | Records super admin role granted. | Active |
super_admin.org_membership.granted | SUPER_ADMIN_ORG_MEMBERSHIP_GRANTED | authorization | Records super admin org membership granted. | Active |
super_admin.org_membership.elevated | SUPER_ADMIN_ORG_MEMBERSHIP_ELEVATED | security | Records super admin org membership elevated. | Active |
service_account.credential.connected | SERVICE_ACCOUNT_CREDENTIAL_CONNECTED | operations | Records service account credential connected. | Active |
service_account.credential.disconnected | SERVICE_ACCOUNT_CREDENTIAL_DISCONNECTED | operations | Records service account credential disconnected. | Active |
Audit resource types
| Resource type | Registry key | Description |
|---|---|---|
secret | SECRET | Audit subject representing secret. |
secretProvider | SECRET_PROVIDER | Audit subject representing secret provider. |
user | USER | Audit subject representing user. |
organization | ORGANIZATION | Audit subject representing organization. |
organizationMember | ORGANIZATION_MEMBER | Audit subject representing organization member. |
workspace | WORKSPACE | Audit subject representing workspace. |
workspaceEnvironment | WORKSPACE_ENVIRONMENT | Audit subject representing workspace environment. |
file | FILE | Audit subject representing file. |
workflow | WORKFLOW | Audit subject representing workflow. |
knowledgeBase | KNOWLEDGE_BASE | Audit subject representing knowledge base. |
kb_page | KB_PAGE | Audit subject representing kb page. |
document | DOCUMENT | Audit subject representing document. |
folder | FOLDER | Audit subject representing folder. |
template | TEMPLATE | Audit subject representing template. |
processFlow | PROCESS_FLOW | Audit subject representing process flow. |
processTemplate | process_flow | Audit subject representing process template. |
schedule | SCHEDULE | Audit subject representing schedule. |
memory | MEMORY | Audit subject representing memory. |
chat | CHAT | Audit subject representing chat. |
webhook | WEBHOOK | Audit subject representing webhook. |
copilotTool | COPILOT_TOOL | Audit subject representing copilot tool. |
integration | INTEGRATION | Audit subject representing integration. |
integrationEntitlement | INTEGRATION_ENTITLEMENT | Audit subject representing integration entitlement. |
mcpServer | MCP_SERVER | Audit subject representing mcp server. |
a2aAgent | A2A_AGENT | Audit subject representing a2a agent. |
a2aTask | A2A_TASK | Audit subject representing a2a task. |
a2aPushConfig | A2A_PUSH_CONFIG | Audit subject representing a2a push config. |
pack_source | PACK_SOURCE | Audit subject representing pack source. |
eventLogReceiver | AUDIT_LOG_SUBSCRIPTION | Audit subject representing event log receiver. |
eventLog | AUDIT_LOG | Audit subject representing event log. |
eventLogRetentionConfig | AUDIT_LOG_RETENTION_CONFIG | Audit subject representing event log retention config. |
auditChain | AUDIT_CHAIN | Audit subject representing audit chain. |
session | SESSION | Audit subject representing session. |
userClearance | USER_CLEARANCE | Audit subject representing user clearance. |
organizationPolicy | ORGANIZATION_POLICY | Audit subject representing organization policy. |
integration_connection | INTEGRATION_CONNECTION | Audit subject representing integration connection. |
dlpHits | DLP_HITS | Audit subject representing dlp hits. |
organizationIntegrationAccount | ORGANIZATION_INTEGRATION_ACCOUNT | Audit subject representing organization integration account. |
dlpPolicy | DLP_POLICY | Audit subject representing dlp policy. |
moderationPolicy | MODERATION_POLICY | Audit subject representing moderation policy. |
User | SCIM_USER | Audit subject representing user. |
Group | SCIM_GROUP | Audit subject representing group. |
Token | SCIM_TOKEN | Audit subject representing token. |
sandbox-egress | SANDBOX_EGRESS | Audit subject representing sandbox egress. |
managed_table | MANAGED_TABLE | Audit subject representing managed table. |
managed-table | MANAGED_TABLE_HYPHENATED | Audit subject representing managed table. |
policy-bundle | POLICY_BUNDLE | Audit subject representing policy bundle. |
data_source | DATA_SOURCE | Audit subject representing data source. |
data-source | DATA_SOURCE_HYPHENATED | Audit subject representing data source. |
data-access-policy | DATA_ACCESS_POLICY | Audit subject representing data access policy. |
iceberg_catalog | ICEBERG_CATALOG | Audit subject representing iceberg catalog. |
chat_conversation | CHAT_CONVERSATION | Audit subject representing chat conversation. |
chat_message_embedding | CHAT_MESSAGE_EMBEDDING | Audit subject representing chat message embedding. |
chat_message | CHAT_MESSAGE | Audit subject representing chat message. |
workflow_plan | WORKFLOW_PLAN | Audit subject representing workflow plan. |
packInstall | PACK_INSTALL | Audit subject representing pack install. |
policyExecutionGrant | POLICY_EXECUTION_GRANT | Audit subject representing policy execution grant. |
authorizationContext | AUTHORIZATION_CONTEXT | Audit subject representing authorization context. |
objectType | OBJECT_TYPE | Audit subject representing object type. |
linkType | LINK_TYPE | Audit subject representing link type. |
actionType | ACTION_TYPE | Audit subject representing action type. |
objectInstance | OBJECT_INSTANCE | Audit subject representing object instance. |
linkInstance | LINK_INSTANCE | Audit subject representing link instance. |
ontologyEffect | ONTOLOGY_EFFECT | Audit subject representing ontology effect. |
ontologyBranch | ONTOLOGY_BRANCH | Audit subject representing ontology branch. |
packCatalog | PACK_CATALOG | Audit subject representing pack catalog. |
serviceAccountCredential | SERVICE_ACCOUNT_CREDENTIAL | Audit subject representing service account credential. |
Workflow lifecycle events
| Action | Registry key |
|---|---|
workflow.scheduled | SCHEDULED |
workflow.started | STARTED |
workflow.paused | PAUSED |
workflow.resumed | RESUMED |
workflow.completed | COMPLETED |
workflow.failed | FAILED |
workflow.terminated | TERMINATED |
workflow.cancelled | CANCELLED |
workflow.purged | PURGED |
Workflow resources: workflowworkflow-executionworkflow-schedule
Integrity events
| Action | Registry key |
|---|---|
integrity.event-log.verification-failed | AUDIT_LOG_VERIFICATION_FAILED |
integrity.event-log.checkpoint-failed | AUDIT_LOG_CHECKPOINT_FAILED |
integrity.dapr-history.verification-failed | DAPR_HISTORY_VERIFICATION_FAILED |
integrity.dapr-history.configuration-mismatch | DAPR_SIGNING_CONFIGURATION_MISMATCH |
integrity.incident.acknowledged | INCIDENT_ACKNOWLEDGED |
integrity.incident.recovered | INCIDENT_RECOVERED |
Integrity resources: event-log-chainevent-log-checkpointdapr-workflow-historyintegrity-incident
Classified events
Audit list, filtered-list, and NDJSON export apply the same clearance rule. If
an event is classified above the viewer's rank, or uses a different
classification scheme, Scrydon returns the action, actor, organization,
timestamp, decision evidence, and integrity-chain fields while replacing the
resource ID and sensitive request context with null. The row includes
redacted: true, and the Audit Log displays a lock.
Select a row in the Audit Log to inspect its event, actor/resource,
policy/classification, request, metadata, and chain-integrity evidence. The
detail panel preserves the same clearance redaction as the list response.
Organizations without user-clearance records keep the previous visibility behavior. Historical rows are not reclassified.
Integrity
New events participate in a mandatory SHA-256 chain for their organization or global security scope. Signed ML-DSA-65 checkpoints can be verified from the Audit Log settings page or through the verification API. Recent valid rows can temporarily report “awaiting a checkpoint”; historical rows created before the cutover are explicitly reported outside the cryptographic proof. There is no configuration switch that disables chain integrity.
Authorization decision evidence is always complete by policy; there is no runtime logging tier. A degraded local enqueue raises an alert and can be reconciled only with the exact original decision ID and payload.