Skip to content

Admin Dashboard: Audit Log

Audit Log records management-plane changes such as creating, updating, deleting, importing, linking, or reloading resources. It answers who changed configuration and when. Agent tool execution belongs in Tool Call Log.

Typical entries include changes to agents, schemas, models, MCP servers, API keys, settings, Knowledge resources, configuration imports, and resilience controls. Read-only requests are not a substitute for a dedicated access log, and model/tool activity is not recorded here.

Use the actor type, action, resource, From, and To filters together. The actor selector distinguishes Admin sessions from API tokens; it does not search individual actor IDs. Results are paginated and display timestamp, actor type and ID, action, resource, and a detail summary. Select an entry to inspect the full details.

FieldHow to use it
TimestampEstablish the order of changes and correlate with an incident window.
Actor type and IDDistinguish an administrator session from an API-key or automation identity.
ActionNarrow the list to creates, updates, deletes, imports, links, or reloads.
ResourceIdentify the affected route or resource family.
DetailsInspect the recorded identifiers and change context.
  1. Bound the time window around the observed change.
  2. Filter the resource type and action.
  3. Identify the actor and inspect the detail payload.
  4. Correlate with Tool Call Log or server logs when the configuration change led to a runtime failure.

The expected result is an attributable administrative event. A missing event can mean the action occurred outside an audited route or outside the selected tenant/time range.

Audit details may contain configuration and identifiers. Restrict access and apply your required retention and backup policy. Records on this page cannot be edited or deleted from Admin.

An audit entry proves that SyntheticBrew recorded an administrative request; it does not by itself prove that a downstream MCP server, model provider, or external system completed an action. Correlate those operations with Tool Call Log and the external system’s audit trail.