Every change, attributed
Audit logging
An immutable record of who changed runner configuration, access and billing, exportable to your SIEM.
Runner configuration is production configuration. Every change to a runner group, an egress policy, a token or a billing setting is recorded with actor, timestamp, source IP and before/after values.
- Immutable, append-only, 13-month retention
- Streaming export to Splunk, Datadog and S3
- Filterable by actor, resource type and time range
Common questions
- What is recorded?
- Every change to runner groups, egress policy, tokens, access and billing, with actor, timestamp, source IP and before/after values.
- Can an administrator delete entries?
- No. The log is append-only with 13-month retention. A log an administrator can edit is a log, not an audit log.
- Can I get it into my SIEM?
- Yes — streaming export to Splunk, Datadog and S3.
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.