Skip to content

Audit log

Open Settings → Audit log to browse security activity recorded on this phone. The log includes automatic decisions and background activity as well as actions you took in the app.

The log keeps 365 days of events. This is separate from Requests, which shows current requests and the 100 most recent completed requests.

Events appear newest first, grouped by date, with a count for each day. Each entry shows the time, event, and relevant recorded context, such as the client, secrets, command, or changed approval mode. Select an entry to open its full details.

The filter starts at All. Select another filter to narrow the timeline:

Filter Included events
All All recorded activity.
Sensitive use Approvals to release sensitive secret data or create Git or SSH signatures, including automatic approvals.
Uploads Secret-upload receipt, decisions, delivery of results, and failures.
Pairings Pairing requests, verification-code decisions, completion, and client confirmations.
Changes Secret and environment-variable edits, key creation and replacement, approval and instruction changes, client changes, and device pairing settings.

Sensitive use selects the approval event for a protected operation. It does not include denials, the earlier receipt of a request, delivery confirmations, or automatic delivery of data marked non-sensitive. Use All to see those stages and to find temporary-access start and end events, secret-list requests, and general request rejections.

Client and secret names are the names recorded with the event. Renaming or removing them later does not rewrite the older audit entries.

A single request can produce separate events when it arrives, when AI reviews it, when a decision is made, and when the client confirms the result. These are stages of one operation, not necessarily repeated uses of a secret.

Decision titles distinguish your approval from approval settings, AI review, temporary access, and combinations of approval sources. Requests containing only non-sensitive data are identified as automatic non-sensitive delivery.

An Approved event records authorization. A later Completed event can confirm that the client received secret data, a signature, or an upload result. Neither reports whether the command or SSH login ultimately succeeded. A failed or missing confirmation does not undo an earlier approval.

Depending on the event, the log retains command arguments and process context, variable names and delivery mappings, non-sensitive environment values, public keys, Git signing content, repository information, approval settings, instructions, AI review inputs and explanations, and errors. Recorded AI review inputs include captured script source when the client supplied it.

Sensitive environment values and private SSH keys are excluded from the structured secret data recorded in request and audit history. Text supplied as a command, reason, description, instruction, or Git signing message remains part of the recorded context. The app does not treat arbitrary text in those fields as a hidden secret value.

Old events are removed automatically after the retention period. The audit browser has no whole-log export or individual-event deletion action; you can copy a selected event as JSON from its details.