Skip to content

Fetch security/audit timeline

GET/tenants/{tenant_id}/security/audit

Returns the chronological security and governance audit event timeline for a tenant. Events include login attempts, permission changes, impersonation events, session revocations, policy updates, and identity config changes. Use for SOC 2 evidence gathering or investigating security incidents.

Request

Path parameters

NameTypeRequiredDescription
tenant_idstringYes

The tenant identifier.

Query parameters

NameTypeRequiredDescription
fromstring (date-time)No

Start of the event range (ISO 8601 datetime, inclusive).

tostring (date-time)No

End of the event range (ISO 8601 datetime, inclusive).

event_typestringNo

Filter to a specific event type (e.g. "impersonation_started", "session_revoke_all").

limitintegerNo

Maximum number of events to return.

Default: 50 · Maximum: 500

Responses

200 Tenant security audit timeline

Content type application/json, array of object · SecurityAuditEventV1.

FieldTypeRequiredDescription
idintegerNo
event_typestringNo

Machine-readable event type (e.g. "impersonation_started", "session_revoke_all", "policy_updated").

tenant_idstringNo
actor_idinteger, nullableNo

ID of the admin or system actor who triggered the event.

outcomestringNo

Result of the action that generated the event.

One of: "success", "failure", "blocked"

metadataobjectNo

Additional event-specific context (e.g. session ID, policy keys changed, IP address).

occurred_atstring (date-time)No

Example

[
  {
    "id": 881,
    "event_type": "impersonation_terminated",
    "tenant_id": "acme",
    "actor_id": 3,
    "outcome": "success",
    "metadata": {
      "session_id": "imp_01HXN8K2V3PABC",
      "reason": "Issue resolved."
    },
    "occurred_at": "2026-04-08T10:47:00Z"
  }
]

404 Tenant not found

Example request

Paths are relative to the control-plane API base URL ($BASE_URL below).

curl -X GET "$BASE_URL/tenants/{tenant_id}/security/audit" \
  -H "Accept: application/json"
Loading