Audit Query
Operate logs, metrics, diagnostics, and audit workflows for audit query.
Immutable authority evidence
Reconstruct who changed what.
Filter tenant-scoped audit events by actor, resource, action, result, and time. Every row comes from the live authority contract.
Query builder
Narrow the evidence before review.
Running a query is read-only. Saving requires an authority preview, the unchanged normalized filter set, explicit confirmation, and tenant concurrency.
Authority preview
Saved evidence view
- Matching evidence
- —
- Cursor
- —
- Redaction
- —
- Expires
- —
- Tenant row
- —
- Normalized filters
- —
No evidence loaded
Run a bounded query or load a saved query.
Rows, counts, and export controls remain empty until the authority returns a complete tenant-scoped page.
Loading authority evidence
Resolving immutable events and saved-query governance…
Not found
This saved query is not visible to the current tenant.
The identifier may be wrong, deleted, expired from visibility, or outside this operator’s tenant boundary.
Permission required
Audit evidence is restricted.
Audit.Read is required by the authority contract to query, preview, save, and inspect evidence.
Authority unavailable
Live audit evidence is temporarily unavailable.
No cached rows or synthetic activity are being substituted.
Invalid authority response
The audit response could not be used safely.
Evidence stays hidden until the authority returns a complete, internally consistent contract.
No matching events
The authority returned a valid empty result.
Broaden a filter or time range; no placeholder audit activity is shown.
Current evidence page
— immutable events
—
Saved query governance
—
- Purpose
- —
- Expires
- —
- Checkpoint
- —
- Rows
- —
- Remediation
- —
Evidence ledger
Actor, action, resource, and time
Client export is unsigned and contains only this authority-returned page.
—Next—Saved-query activity
Query lifecycle evidence
Loading saved-query lifecycle…
Result rows remain available, but lifecycle evidence could not be loaded.