Exports and audit
Audit log
Every action that changes your workspace or your data writes one append-only row: what happened, who did it, when, and the facts that make it provable afterwards. It is readable over the API on every plan, and downloadable as a file where your plan carries export.
What is recorded
| Event | Written when |
|---|---|
corpus.delete | A whole document base and everything under it is deleted. Carries the per-tier receipt. |
document.delete | One document is deleted. Same per-tier receipt. |
corpus.delete_compensation | A delete landed mid-onboard and the worker cleaned up after itself. |
ingest.commit | An upload manifest is committed into a document base. |
upload_credentials.issued | Direct-to-storage upload credentials were vended. |
apikey.create, apikey.revoke | An API key is minted or turned off. Name, display prefix and scopes, never the secret. |
source.created, source.updated, source.deleted, source.sync | A connected bucket or folder is registered, changed, removed, or synced. |
webhook.created, webhook.deleted, webhook.delivery | A delivery endpoint is subscribed, removed, or delivered to. |
enterprise.sso_configured, enterprise.sso_removed | Single sign-on is configured or switched off. Carries the issuer, the domains and whether it is enforced. |
enterprise.ip_allowlist_set | The IP allowlist changes. Carries the list saved and whether a lockout was confirmed. |
enterprise.kms_key_set | Your own KMS key is set or cleared. |
legal.accept | An admin accepts the Service Agreement or the DPA. See Terms and DPA acceptance. |
Rows are append-only. Nothing edits or removes one, and a delete receipt deliberately outlives the data it describes.
Reading it
Newest first, any member of the workspace, filtered strictly on the workspace the credential belongs to:
curl -s "https://api.engramdynamics.org/audit?limit=50" \
-H "Authorization: Bearer <your key>"
[
{
"id": "9f1c...",
"event": "enterprise.ip_allowlist_set",
"corpus_id": null,
"detail": "{\"cidrs\": [\"203.0.113.0/24\"], \"confirmed_lockout\": false}",
"created_at": "2026-09-13T09:41:22Z"
}
]
limit runs from 1 to 1000 and defaults to 100, so no client can page the whole table in one call. detail is compact JSON carrying that event's own facts, with keys sorted so two receipts diff cleanly.
Under /v1 the same route gains the versioned conventions: limit and cursor, an {"items": [...], "next_cursor": ...} envelope, and the versioned error shape.
curl -s "https://api.engramdynamics.org/v1/audit?limit=50" \
-H "Authorization: Bearer <your key>"
Deletion receipts
Deletions get a route of their own, because a deletion receipt is the one row a customer is entitled to go and find after the fact, and the obvious place to look for it is impossible by construction: the document base whose id you would use is exactly what the delete removed. So receipts are addressable at the workspace level.
curl -s "https://api.engramdynamics.org/audit/deletions?limit=20" \
-H "Authorization: Bearer <your key>"
Each row's detail carries the per-tier outcome, with the same tier names as the published erasure timeline, so a receipt and the timeline read against each other line for line. Data lifecycle and deletion has that table and what each tier means.
This route is workspace-admin only, rather than any member: the listing names every document base the workspace has ever deleted, which is a workspace-wide history and not the caller's own activity.
What is not in it
- No document content. Rows carry ids, counts, names and settings. Never the text of anything you loaded.
- No other workspace. The workspace comes from the credential, never from a parameter, so there is no id in these routes for anyone to change.
- No operator sweeps. Our own store-wide housekeeping is recorded against a system workspace and is never returned to a customer.
- Errors are sanitized. Where a delete records a serving-plane failure, the row keeps the failure class and the affected ids so it can be recovered, not internal addresses.
Next
Exports turns this log, and your usage, into files you can hand to a reviewer or load into a pipeline.