Docs / Surface / audit-log

Audit Log

The Audit Log records administrative changes made to your Surface account — who did what, to which resource, and when. It answers questions like when did this profile's allowed types change? and who revoked that API key?

What gets recorded

Configuration and access changes, rather than scan traffic:

Individual scans are not audit entries. Those live in Scan History, which keeps the scan record itself.

What each entry shows

Column Meaning
Timestamp When the change was made
Actor The user or API key that made it
Action create, update, delete, and similar
Resource The type and name of the thing that changed

Retention

Audit entries are kept for 90 days on every plan, independent of the retention window that applies to scan history. This is deliberate: the record of who changed what outlives the data the change affected. See Data Retention.