Guardrails & security
Audit logs
An immutable, per-tenant record of every sensitive action.
Every sensitive action is written to an immutable audit_logs table, scoped per
organization and indexed for per-tenant queries.
Recorded events include:
- permission denials (every 403 from the permission guard)
- user and role changes
- subscription and billing events
- provider key rotations and revocations
- login success and failure
Audit logs are exportable for compliance review. Browse them in the dashboard under Audit Logs.