SISuperintelligenceDocs

Search docs

Search every page of the documentation.

API reference

Audit log

Read an organization's audit log.

See Audit log for every recorded action.

GET /v1/orgs/:orgId/audit

One page of the audit log, newest first. Filter by action (an action or a category), actor or target. The first page also returns retentionDays.

Auth: user access token or platform agent key · Scope: audit:read

Path parameterDescription
:orgIdOrganization id (org_…).
Query parameterTypeRequiredDefaultNotes
cursorstringNoup to 4,096 characters
actionstringNomatches ^[a-z_]{1,32}(\.[a-z_]{1,32})?$
actorstringNo1–512 characters
targetstringNomatches ^[a-z_]{1,32}:[^\s]{1,512}$
limitintegerNo501–100; coerced from a string

Response 200

{
  events: {
    eventId: string
    orgId: string
    action: string
    actor: {
      type: "user" | "device" | "key" | "system"
      id: string
      label?: string
    }
    target: {
      type: string
      id: string
      label?: string
    }
    metadata?: {
      [key: string]: unknown
    }
    ip?: string
    userAgent?: string
    createdAt: number
  }[]
  cursor: null | string
  retentionDays?: number
}

Errors

StatusMessage
400Invalid cursor

GET /v1/orgs/:orgId/audit/export

Daily JSON Lines export of the audit log into one of the org's buckets (audit/<yyyy-mm-dd>.jsonl).

Auth: user access token or platform agent key · Scope: audit:read

Path parameterDescription
:orgIdOrganization id (org_…).

Response 200

{
  export: {
    bucketId: null | string
    bucket: null | {
      name: string
      region: string
      prefix: string
    }
    pendingDays: string[]
  }
}

Errors

StatusMessage
404Organization not found

PUT /v1/orgs/:orgId/audit/export

Turns the daily export on (bucketId: an active bucket of the org) or off (null). Owners and admins.

Auth: user access token or platform agent key · Scopes: audit:read, org:write

Path parameterDescription
:orgIdOrganization id (org_…).

Request body

FieldTypeRequiredNotes
bucketIdstringYes1–64 characters; can be null

Response 200

{
  export: {
    bucketId: null | string
    bucket: null | {
      name: string
      region: string
      prefix: string
    }
    pendingDays: string[]
  }
}

Errors

StatusMessage
400Choose an active bucket of this organization.
404Organization not found