On this page
- 01What you'll do
- 02The four views
- 03What the Control Plane Audit Log records
- 04Find who changed something
- 05Find out why requests are blocked
- 06Read the Bypass & Error Audit
- 07Who sees raw evidence
- 08Export the log
- 09Three questions, three answers
- 10Keep the log useful
- 11A weekly review
- 12If something goes wrong
01
What you'll do
When something changes or breaks, the first question is what happened and who did it. In about ten minutes you will learn the four views on the Audit tab, search them, and export the log.
- Read the four cards on the Audit tab
- Find who changed a policy, key, or credential
- Find out why requests are being blocked
- Export the log for a review
02
The four views
The Audit tab answers four different questions, one card each.
| Card | Answers |
|---|---|
| Approval queue | What is waiting for a decision, and what was decided |
| Policy Violations | Which rules blocked requests, grouped by reason, policy, and app, over the last 30 days |
| Bypass & Error Audit | Rare, higher-severity events such as a guardrail finding that was allowed through |
| Control Plane Audit Log | Every configuration and key action: who did what, and when |
| Left card | Right card |
|---|---|
| Approval queue | Policy Violations |
| Bypass & Error Audit | Control Plane Audit Log |
The four cards, as they sit on the tab.
03
What the Control Plane Audit Log records
Changes to how your gateway is set up are recorded with who made them.
| Area | Recorded actions |
|---|---|
| Policies | Create, update, and delete |
| Bindings | Create, update, and delete |
| Virtual keys | Create, update, rotate, and revoke |
| Provider credentials | Create, validate, rotate, and revoke |
| Edge instances | Register, create, and revoke |
| Tool servers | Create, update, and delete; tool definition approvals and rejections |
| Guardrail profiles | Publish |
| Approvals | Request, approve, and reject |
| Exact cache | Invalidate |
The card refreshes about every thirty seconds.
04
Find who changed something
Search and filter turn the log into an answer.
- 1
Open the Control Plane Audit Log
It is on the lower right of the Audit tab.
- 2
Filter by action
Choose an action, such as policy.update.
- 3
Search
Type a policy name, key name, or person.
- 4
Open a row
See the actor, the time, the target, and what changed.
Why did spend jump on Tuesday?
The Explorer shows spend rising at 14:00. In the audit log, a policy.update at 13:52 raised the daily budget and the allowed models on the support policy. The row names the person and links the change. You now know what changed, who changed it, and whether an approval was involved.
05
Find out why requests are blocked
Policy Violations groups the blocks so you see patterns instead of single events.
- 1
Open Policy Violations
Each row is a group: a reason, a policy, and an app.
- 2
Filter
Type a reason, a policy, or an app to narrow the list.
- 3
Drill in
Choose a group to see recent requests that match it.
- 4
Expand a request
See the details the gateway recorded, such as the limit and what was requested.
06
Read the Bypass & Error Audit
This card holds rare events that deserve a person's attention.
- Findings that a guardrail allowed through, such as a secret in Observe
- Cases where a guardrail check could not run
- Approval bypasses
Filter by severity: Critical, Error, Warning, or Info. Routine guardrail activity is not recorded here, so the card stays short enough to read.
07
Who sees raw evidence
Some rows carry hashes and identifiers that identify a request.
| Role | Sees |
|---|---|
| Owner, admin | The full row, including raw evidence |
| Other roles | The row without raw hash and identifier details |
08
Export the log
Owners and admins can export the Control Plane Audit Log for a review or a ticket.
- 1
Open the Control Plane Audit Log
Set the filter you need.
- 2
Choose Export
The log downloads as a file.
- 3
Attach it
Add it to the review, ticket, or evidence folder.
09
Three questions, three answers
The same views answer most questions people ask.
| Question | Where to look | What to read |
|---|---|---|
| Who raised the budget? | Control Plane Audit Log | Filter policy.update and open the row |
| Was the change approved? | Approval queue, Approved filter | The approver, time, and note |
| Why is the support app seeing 403s? | Policy Violations | The group for that app and its reason |
| Did a guardrail let something through? | Bypass & Error Audit | Rows marked Warning or higher |
| Who created this key? | Control Plane Audit Log | Filter gateway_key.create |
10
Keep the log useful
A log helps in proportion to the habits around it.
- Name policies, keys, and credentials so a row reads on its own
- Write a reason when you reject an approval
- Export the log monthly if your process needs a copy outside the console
- Review who holds the owner and admin roles each quarter
11
A weekly review
A short pass keeps surprises small.
- 1
Approval queue
Clear anything pending.
- 2
Policy Violations
Look at the top groups. Fix the ones that block real work.
- 3
Bypass & Error Audit
Read anything marked Error or Critical.
- 4
Control Plane Audit Log
Scan policy, credential, and key changes for any you did not expect.
12
If something goes wrong
Most questions are about what is recorded.
| What you see | Likely cause | Fix |
|---|---|---|
| A change is missing from the log | It was made outside the areas the log covers | Check the table above |
| No Export button | Your role is not owner or admin | Ask an owner or admin |
| Policy Violations is empty | Nothing was blocked in the last 30 days | That is good news |
| Raw evidence is hidden | Your role is below admin | Ask an owner or admin |