Skip to content
Foxx Cyberfoxxcyber/docs

Audit log

The workspace-wide activity trail — every create, update, delete and import, who did it, and exactly which fields changed.

Every write in Bedrock RMF is recorded twice: in the package's own Activity tab, and in the workspace-wide Audit Log under the Admin Panel. The audit log is the one an assessor will ask for — who changed this POA&M's completion date, and when? — and it is the one you cannot edit.

Reading the log

Admin → Audit Log — Workspace-wide activity trail — is a paginated table (?page= in the URL) with two filters, user and action, and these columns:

ColumnWhat it holds
TimestampWhen the change was committed
UserThe account that made it — a person, or a team's AI Agent service user when the change came through an API key
Actioncreate, update, delete, import, …
Entity TypeWhat was touched: poam, cloud_service, implementation, …
Entity IDThe record's identifier
DetailsJSON of the changed fields, plus the packageId the record belongs to

Admin → Audit Log with user and action filters

Filter by user to reconstruct one person's day; filter by action delete to review everything that was removed; combine with a package's Activity tab when you need the same trail scoped to one system.

What it is good for

  • Assessment support — the JSON in Details shows the before and after of a field, so you can show an assessor that an implementation statement was updated on a given date and by whom.
  • Change control — deletions of evidence, POA&Ms or assets are visible here even after the record is gone from its list.
  • API oversight — anything an API key did appears under the team's AI Agent user, so automated changes are never mixed in with a person's.

Entries are permanent

There is no way to edit or delete an audit entry from the application; it grows with the database and is backed up with it. If your retention policy requires pruning, do it against a database export, not the live log.

  • Changing a password revokes a user's other sessions, and enrolment in two-factor shows in the MFA column of Admin → Users — see Users, teams and roles.
  • Key creation, rotation and revocation are logged too — see API keys.

Last updated August 27, 2026