vault/Audit Log

Audit Log

Monitor, filter, investigate, and export activity across your SikkerKey vault.

Updated today

The Audit Log gives you a live, searchable history of activity in your vault. Use it to follow secret access, review security changes, investigate authentication events, and prepare records for compliance or incident review.

The dashboard updates the Audit Log as new events arrive, so your current view stays aligned with recent vault activity.


#What the Audit Log records

SikkerKey records events across secrets, machines, projects and applications, authentication, sessions, organization membership and SSO, AI agents, billing, webhooks, IP allowlists, integrations, temporary secrets, and automated vault activity.

Each event is added to the vault’s chronological history with the information needed to understand what happened and where it came from.

Field

What it tells you

Time

When the event occurred. The dashboard uses your local time; exported files use UTC.

Severity

The importance of the event: Info, Low, Medium, High, or Critical.

Action

The recorded activity, such as Secret Read, Machine Approve, Login Failed, or Project Freeze.

Detail

A readable description with the relevant names, outcome, or reason.

Actor

The user, machine, AI agent, or SikkerKey system process responsible for the activity.

Source IP

The network address associated with the request or event.


#Open and browse the Audit Log

Sign in to the SikkerKey dashboard and select Audit Log in the sidebar.

Review the newest events at the top of the table.

Use Prev and Next to move through the complete set of matching events.

Select the Time, Action, or Source IP column heading to change the sort order. Select the same heading again to switch between ascending and descending order.

#Understand severity

Severity

How to use it

Info

Routine activity, including successful reads, logins, rotations, and everyday configuration changes.

Low

Administrative or setup activity worth retaining as part of the vault history.

Medium

Meaningful security, access, lifecycle, or configuration changes that may deserve review.

High

Sensitive changes, denied operations, failed security checks, and destructive actions that deserve prompt attention.

Critical

Highest-impact security and destruction events, including authentication failures, canary triggers, vault or project destruction, and account-protection events.


#Filter and investigate events

Filters work together, making it easy to move from a broad review to a focused investigation.

  • Search details: enter a name, identifier, or phrase contained in the event detail.

  • Source IP: enter an IP address to show events from that exact address.

  • Action: select one or more recorded actions.

  • Severity: select one or more severity levels.

  • Time: choose Last hour, Last 24 hours, Last 7 days, or Last 30 days.

  • Actor: choose all users, machines, AI agents, or system activity, or search for a specific named actor.

Your active filters appear as chips above the table. Remove individual chips to broaden the results, or select Clear all to return to the full log.

#Review activity for a specific resource

You can open a focused activity history directly from the resource you are investigating. These views support action, severity, time, and detail filters.

  • Secrets: open a secret’s History view and select Audit to review reads, updates, rotations, renames, and lifecycle events for that secret.

  • Machines: open History for a machine and select Audit to review activity performed by or involving that machine.

  • AI agents: open History for an AI agent and select Audit to review its management activity and identity changes.

  • Organization members: open History from a member row to review that member’s activity in the organization.


#Export audit events

Export a complete filtered event set for analysis, reporting, evidence collection, or import into another security tool.

Select Export at the top of the Audit Log.

Choose CSV, JSON, or TXT.

Select a time period: 24 hours, 7 days, 30 days, 90 days, all time, or a custom date range.

Refine the export by action, actor, severity, source IP, or detail search.

Review the matching event count and sample output, then select Export.

Format

Best for

CSV

Spreadsheets, reporting workflows, and security-tool imports.

JSON

Structured processing and integrations. The file includes the export time, selected range, active filters, event count, and event records.

TXT

A readable, line-oriented record with an export summary followed by each event.

Each download contains every event that matches the selected range and filters, ordered from newest to oldest.

The export modal.
The export modal.

#Control who can view audit activity

Vault owners can review activity across the entire active vault. Organization members receive audit access through their vault role.

  • View audit log gives a member access to their own activity in the vault.

  • View others expands the log to activity from every actor in the vault.

Use the organization’s vault roles to assign the level of audit visibility each member needs. Resource-specific histories follow the member’s access to the corresponding secret, machine, AI agent, or organization member area.


#Retention

Your subscription plan sets the standard audit-retention period for the vault. High-severity events are retained for twice that period, and Critical events remain available as a long-term security record.