What gets logged
Viewing the log
Storage
Audit events are stored as newline-delimited JSON (JSONL) files in the vault directory:- Timestamp (milliseconds since epoch)
- Event type
- Relevant IDs (secret, credential, capability)
- Execution context (workspace, group, client IP)