Documentation

Learn how to set up and get the most out of Viktor.

Audit Logs

Turn on the customer audit log for an Enterprise workspace, choose what it captures, export events through the API, and review approval history.

The customer audit log is a record of what happens in your workspace: access and configuration changes, and the integration tool calls Viktor makes. Your workspace owns the trail and exports it through the Public API. The Audit Logs page also shows the approval history for protected actions.

Who can use it

Audit logs need all of the following:

  • An Enterprise workspace. See Plans and credits.
  • An admin role. The Audit Logs tab is hidden from members.

If your workspace is not eligible, the Audit Logs tab does not appear in Settings. Opening app.viktor.com/settings/audit-logs directly shows "Customer audit logs are not available for this workspace yet."

Turn on audit logging

  1. Open Settings and select Audit Logs (or go to app.viktor.com/settings/audit-logs).
  2. Select Enable Audit Logs. Viktor confirms with Audit logging enabled.
  3. Choose a Capture Level (see below).

The page shows:

  • Status: Enabled or Disabled.
  • Capture health: Healthy or Degraded. When capture is degraded, a warning shows since when, and the latest capture error.

To stop recording, select Disable Audit Logs. Turning audit logging on or off, and changing the capture level, are themselves recorded as events.

Choose a capture level

The Capture Level card appears while audit logging is on:

  • Full: "Access and configuration changes plus all data activity: tool calls, data in, data out."
  • Governance only: "Access and configuration changes only. Data activity is not recorded."

Switching to Governance only asks you to confirm. New data activity stops being recorded and can't be recovered later. Events already recorded are kept until they expire. Access and configuration changes are always recorded. Switching back to Full loses nothing.

If you turn audit logging off and on again, it comes back at the capture level you chose before.

What gets recorded

Examples of events in the trail:

  • Team changes: invites created and revoked, role changes and member removals, including refused attempts. See Team members and roles.
  • Audit settings: enabling or disabling the log and changing the capture level.
  • API keys: a key being created, edited, having its scopes changed, rotated, revoked or deleted.
  • Refused API key use: a request refused because the key was missing a scope, inactive, expired, had the wrong secret, or belonged to a disabled user. These events include the client IP address and browser or client type. Repeated refusals for the same key and reason are grouped rather than recorded one by one.
  • Audit exports: a key reading the audit log through the API. Access to the trail is part of the trail.
  • Data activity (with Full capture): integration tool calls, and the data going in and out.

Export audit events

There is no download button in the app. The Pull API card explains: "Audit events are available only through the public API. Create a team API key with audit read access, then poll the events endpoint with the returned cursor."

  1. Open Settings → API Keys and create a Team API key with the audit:read scope. Only admins can create team keys, and audit:read can't be added to a personal key.
  2. Call GET /api/public/v1/audit/events with the key.
  3. Pass each response's next_cursor as the next request's cursor query parameter until you have every page.

GET /api/public/v1/audit/digests returns daily integrity digests, so you can check that no event was added, removed or edited. The request details are in the Public API reference. Audit logging must be enabled for the export to work.

How long events are kept

Audit events are kept for 400 days, then deleted.

Approval history

Below the audit settings, Approval history lists "every action a teammate approved or rejected, with who decided, where, the policy in force, the resulting status, and a link to the originating message." Each record shows Decided by, Response from, Policy at decision, Policy at execution, Decided at and Executed at, plus the proposed arguments.

Approval history appears on the same page, for the same admins and Enterprise workspaces. If nothing has been approved or rejected yet, it shows No approvals yet. See Approvals for how approvals work.

Limits by plan and permission

Requirement
See the Audit Logs tabAdmin, Enterprise workspace
Enable, disable, change capture levelAdmin, Enterprise workspace
Export events and digestsTeam API key with audit:read, audit logging enabled
Retention400 days

Common problems

  • No Audit Logs tab: you are not an admin, or your workspace is not on Enterprise. See Enterprise plans.
  • "Customer audit logs are not available for this workspace yet.": the same cause, reached through a direct link.
  • The export returns 403: use a team key, not a personal key, and make sure it has audit:read and that audit logging is enabled. The Public API lists the error codes.
  • Capture health shows Degraded: check the capture error on the page. If it continues, contact support with your Team ID from Team settings.
  • Missing tool-call events: check the capture level. Governance only does not record data activity, and events from before a switch back to Full can't be recovered.

Related

Get Started for Free