Management audit
SubLane guide: management audit.
Use this when investigating who changed a management setting. To inspect model calls instead, see Everyday use.
Administrators open Administration → Audit log to inspect changes to gateway keys, pools, members, subscription accounts and access settings. Members cannot access the page or API. Request history remains separate: it describes model calls rather than management changes.
Recorded actions
- Personal key creation, metadata changes, full-key retrieval and permanent revocation. Full-key retrieval logs only actor/target metadata, never the value.
- Pool creation, model-policy changes and member pool grants.
- Member creation, enable/disable, rate/concurrency changes and password reset.
- Personal password changes and local administrator password recovery.
- Subscription account import/authorization, reauthorization, enable/disable, deletion, concurrency changes, proxy binding and manual cooldown reset.
- Workspace proxy creation, batch import, update, individual deletion and batch deletion of recently failed, unbound proxies.
Each event contains the authenticated actor's ID, username/role snapshot, source (user or local), a fixed action, resource type/ID, outcome and timestamp. Failed authenticated attempts to recognized mutation endpoints include the HTTP status. Invalid/unrecognized target paths, origin rejection, public setup/login/logout, OAuth initiation/cancellation, read-only checks, automatic credential refresh and runtime bookkeeping are outside this log. Initial data and past actions are not backfilled.
There are no request/response bodies, credentials, password hashes, full keys, OAuth parameters, raw URLs/errors, account email addresses, or before/after secret snapshots. Account IDs are opaque SubLane record IDs; deleted targets remain identifiable by ID. Failed account import/OAuth completion attempts omit the target ID because it cannot be obtained safely from an untrusted body.
Successful events commit in the same transaction as the mutation. A failed audit write rolls back the change. Domain background operations without a user actor do not invent one. Authenticated HTTP failures are best-effort, with a bounded persistence timeout; persistence failure emits a fixed server diagnostic without request data. Local recovery records local-cli as the actor rather than falsely attributing it to the administrator.
Example audit log with synthetic management events:

Storage and API
The consolidated schema creates an audit table with monotonic event IDs. Keep the latest 90 days, capped at 10,000 events; pruning runs on inserts and list reads. There is no deletion API, external logging service or background polling dependency. Retention is a bounded operational record, not an immutable external archive.
GET /api/audit?cursor=0&resource=&outcome= requires an enabled administrator browser session and returns events plus next_cursor. Pages contain at most 50 entries, newest first. Resources include key, group, member, user, account, and proxy; outcomes are success or failure; an empty filter selects all. Invalid filters return HTTP 400. The frontend loads records only on navigation, explicit refresh, filter changes or pagination.