Audit events
Privileged actions emit structured events, ready for your SIEM.
WhereConsole
Introduced Apr 20, 2026
Audit events
11:02 cluster-admin granted → m.chen
11:09 llm provider credential changed
11:14 secret written gh-deploy-token
structured · streamed to your SIEM
How it works
Privileged actions leave records.
Admin grants, organization deletions, provider credential changes, secret writes — structured events, on the record.
Ready for your SIEM.
Shippable to wherever your other audit trails already live.
See it on your own cluster.
Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.