What gets logged
| Event type | Trigger |
|---|---|
| Secret created | aivault secrets create |
| Secret rotated | aivault secrets rotate |
| Secret deleted | aivault secrets delete |
| Secret pinned | Auto-pin to registry provider |
| Group attached | aivault secrets attach-group |
| Group detached | aivault secrets detach-group |
| Capability invoked | aivault invoke, json, markdown |
| Master key rotated | aivault rotate-master |
Viewing the log
Storage
Audit events are stored as newline-delimited JSON (JSONL) files in the vault directory:- Timestamp (milliseconds since epoch)
- Event type
- Relevant IDs (secret, credential, capability)
- Execution context (workspace, group, client IP)