All guides

Read the Audit Log and Prove Who Changed What

Use the Audit tab to see why a request was blocked and what the gateway did, then export the log for review.

10 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll do
  2. 02The four views
  3. 03What the Control Plane Audit Log records
  4. 04Find who changed something
  5. 05Find out why requests are blocked
  6. 06Read the Bypass & Error Audit
  7. 07Who sees raw evidence
  8. 08Export the log
  9. 09Three questions, three answers
  10. 10Keep the log useful
  11. 11A weekly review
  12. 12If something goes wrong

01

What you'll do

When something changes or breaks, the first question is what happened and who did it. In about ten minutes you will learn the four views on the Audit tab, search them, and export the log.

  • Read the four cards on the Audit tab
  • Find who changed a policy, key, or credential
  • Find out why requests are being blocked
  • Export the log for a review

02

The four views

The Audit tab answers four different questions, one card each.

CardAnswers
Approval queueWhat is waiting for a decision, and what was decided
Policy ViolationsWhich rules blocked requests, grouped by reason, policy, and app, over the last 30 days
Bypass & Error AuditRare, higher-severity events such as a guardrail finding that was allowed through
Control Plane Audit LogEvery configuration and key action: who did what, and when
AI → Audit
Left cardRight card
Approval queuePolicy Violations
Bypass & Error AuditControl Plane Audit Log

The four cards, as they sit on the tab.

Approval queue, Policy Violations, Bypass & Error Audit, and the Control Plane Audit Log.

03

What the Control Plane Audit Log records

Changes to how your gateway is set up are recorded with who made them.

AreaRecorded actions
PoliciesCreate, update, and delete
BindingsCreate, update, and delete
Virtual keysCreate, update, rotate, and revoke
Provider credentialsCreate, validate, rotate, and revoke
Edge instancesRegister, create, and revoke
Tool serversCreate, update, and delete; tool definition approvals and rejections
Guardrail profilesPublish
ApprovalsRequest, approve, and reject
Exact cacheInvalidate

The card refreshes about every thirty seconds.

04

Find who changed something

Search and filter turn the log into an answer.

  1. 1

    Open the Control Plane Audit Log

    It is on the lower right of the Audit tab.

  2. 2

    Filter by action

    Choose an action, such as policy.update.

  3. 3

    Search

    Type a policy name, key name, or person.

  4. 4

    Open a row

    See the actor, the time, the target, and what changed.

Why did spend jump on Tuesday?

The Explorer shows spend rising at 14:00. In the audit log, a policy.update at 13:52 raised the daily budget and the allowed models on the support policy. The row names the person and links the change. You now know what changed, who changed it, and whether an approval was involved.

05

Find out why requests are blocked

Policy Violations groups the blocks so you see patterns instead of single events.

  1. 1

    Open Policy Violations

    Each row is a group: a reason, a policy, and an app.

  2. 2

    Filter

    Type a reason, a policy, or an app to narrow the list.

  3. 3

    Drill in

    Choose a group to see recent requests that match it.

  4. 4

    Expand a request

    See the details the gateway recorded, such as the limit and what was requested.

06

Read the Bypass & Error Audit

This card holds rare events that deserve a person's attention.

  • Findings that a guardrail allowed through, such as a secret in Observe
  • Cases where a guardrail check could not run
  • Approval bypasses

Filter by severity: Critical, Error, Warning, or Info. Routine guardrail activity is not recorded here, so the card stays short enough to read.

07

Who sees raw evidence

Some rows carry hashes and identifiers that identify a request.

RoleSees
Owner, adminThe full row, including raw evidence
Other rolesThe row without raw hash and identifier details

08

Export the log

Owners and admins can export the Control Plane Audit Log for a review or a ticket.

  1. 1

    Open the Control Plane Audit Log

    Set the filter you need.

  2. 2

    Choose Export

    The log downloads as a file.

  3. 3

    Attach it

    Add it to the review, ticket, or evidence folder.

09

Three questions, three answers

The same views answer most questions people ask.

QuestionWhere to lookWhat to read
Who raised the budget?Control Plane Audit LogFilter policy.update and open the row
Was the change approved?Approval queue, Approved filterThe approver, time, and note
Why is the support app seeing 403s?Policy ViolationsThe group for that app and its reason
Did a guardrail let something through?Bypass & Error AuditRows marked Warning or higher
Who created this key?Control Plane Audit LogFilter gateway_key.create

10

Keep the log useful

A log helps in proportion to the habits around it.

  • Name policies, keys, and credentials so a row reads on its own
  • Write a reason when you reject an approval
  • Export the log monthly if your process needs a copy outside the console
  • Review who holds the owner and admin roles each quarter

11

A weekly review

A short pass keeps surprises small.

  1. 1

    Approval queue

    Clear anything pending.

  2. 2

    Policy Violations

    Look at the top groups. Fix the ones that block real work.

  3. 3

    Bypass & Error Audit

    Read anything marked Error or Critical.

  4. 4

    Control Plane Audit Log

    Scan policy, credential, and key changes for any you did not expect.

12

If something goes wrong

Most questions are about what is recorded.

What you seeLikely causeFix
A change is missing from the logIt was made outside the areas the log coversCheck the table above
No Export buttonYour role is not owner or adminAsk an owner or admin
Policy Violations is emptyNothing was blocked in the last 30 daysThat is good news
Raw evidence is hiddenYour role is below adminAsk an owner or admin

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial