SubLaneSubLane

Management audit

SubLane guide: management audit.

Use this when investigating who changed a management setting. To inspect model calls instead, see Everyday use.

Administrators open Administration → Audit log to inspect changes to gateway keys, pools, members, subscription accounts and access settings. Members cannot access the page or API. Request history remains separate: it describes model calls rather than management changes.

Recorded actions

  • Personal key creation, metadata changes, full-key retrieval and permanent revocation. Full-key retrieval logs only actor/target metadata, never the value.
  • Pool creation, model-policy changes and member pool grants.
  • Member creation, enable/disable, rate/concurrency changes and password reset.
  • Personal password changes and local administrator password recovery.
  • Subscription account import/authorization, reauthorization, enable/disable, deletion, concurrency changes, proxy binding and manual cooldown reset.
  • Workspace proxy creation, batch import, update, individual deletion and batch deletion of recently failed, unbound proxies.

Each event contains the authenticated actor's ID, username/role snapshot, source (user or local), a fixed action, resource type/ID, outcome and timestamp. Failed authenticated attempts to recognized mutation endpoints include the HTTP status. Invalid/unrecognized target paths, origin rejection, public setup/login/logout, OAuth initiation/cancellation, read-only checks, automatic credential refresh and runtime bookkeeping are outside this log. Initial data and past actions are not backfilled.

There are no request/response bodies, credentials, password hashes, full keys, OAuth parameters, raw URLs/errors, account email addresses, or before/after secret snapshots. Account IDs are opaque SubLane record IDs; deleted targets remain identifiable by ID. Failed account import/OAuth completion attempts omit the target ID because it cannot be obtained safely from an untrusted body.

Successful events commit in the same transaction as the mutation. A failed audit write rolls back the change. Domain background operations without a user actor do not invent one. Authenticated HTTP failures are best-effort, with a bounded persistence timeout; persistence failure emits a fixed server diagnostic without request data. Local recovery records local-cli as the actor rather than falsely attributing it to the administrator.

Example audit log with synthetic management events:

Audit log showing key, member permission and pool changes

Storage and API

The consolidated schema creates an audit table with monotonic event IDs. Keep the latest 90 days, capped at 10,000 events; pruning runs on inserts and list reads. There is no deletion API, external logging service or background polling dependency. Retention is a bounded operational record, not an immutable external archive.

GET /api/audit?cursor=0&resource=&outcome= requires an enabled administrator browser session and returns events plus next_cursor. Pages contain at most 50 entries, newest first. Resources include key, group, member, user, account, and proxy; outcomes are success or failure; an empty filter selects all. Invalid filters return HTTP 400. The frontend loads records only on navigation, explicit refresh, filter changes or pagination.