Docs / Surface / audit-log
Audit Log
The Audit Log records administrative changes made to your Surface account — who did what, to which resource, and when. It answers questions like when did this profile's allowed types change? and who revoked that API key?
What gets recorded
Configuration and access changes, rather than scan traffic:
- Scan profile changes — created, updated, deleted
- API key lifecycle — created, revoked, linked to a different profile
- Role and user changes — roles created or edited, roles assigned
- IP blocks and unblocks
Individual scans are not audit entries. Those live in Scan History, which keeps the scan record itself.
What each entry shows
| Column | Meaning |
|---|---|
| Timestamp | When the change was made |
| Actor | The user or API key that made it |
| Action | create, update, delete, and similar |
| Resource | The type and name of the thing that changed |
Retention
Audit entries are kept for 90 days on every plan, independent of the retention window that applies to scan history. This is deliberate: the record of who changed what outlives the data the change affected. See Data Retention.
Related
- Access Control — the roles and keys whose changes are recorded here
- Scan History — the scans themselves, not the configuration around them
Tendrl