Exports and audit

Audit log

Every action that changes your workspace or your data writes one append-only row: what happened, who did it, when, and the facts that make it provable afterwards. It is readable over the API on every plan, and downloadable as a file where your plan carries export.

What is recorded

EventWritten when
corpus.deleteA whole document base and everything under it is deleted. Carries the per-tier receipt.
document.deleteOne document is deleted. Same per-tier receipt.
corpus.delete_compensationA delete landed mid-onboard and the worker cleaned up after itself.
ingest.commitAn upload manifest is committed into a document base.
upload_credentials.issuedDirect-to-storage upload credentials were vended.
apikey.create, apikey.revokeAn API key is minted or turned off. Name, display prefix and scopes, never the secret.
source.created, source.updated, source.deleted, source.syncA connected bucket or folder is registered, changed, removed, or synced.
webhook.created, webhook.deleted, webhook.deliveryA delivery endpoint is subscribed, removed, or delivered to.
enterprise.sso_configured, enterprise.sso_removedSingle sign-on is configured or switched off. Carries the issuer, the domains and whether it is enforced.
enterprise.ip_allowlist_setThe IP allowlist changes. Carries the list saved and whether a lockout was confirmed.
enterprise.kms_key_setYour own KMS key is set or cleared.
legal.acceptAn admin accepts the Service Agreement or the DPA. See Terms and DPA acceptance.

Rows are append-only. Nothing edits or removes one, and a delete receipt deliberately outlives the data it describes.

Reading it

Newest first, any member of the workspace, filtered strictly on the workspace the credential belongs to:

curl -s "https://api.engramdynamics.org/audit?limit=50" \
  -H "Authorization: Bearer <your key>"
[
  {
    "id": "9f1c...",
    "event": "enterprise.ip_allowlist_set",
    "corpus_id": null,
    "detail": "{\"cidrs\": [\"203.0.113.0/24\"], \"confirmed_lockout\": false}",
    "created_at": "2026-09-13T09:41:22Z"
  }
]

limit runs from 1 to 1000 and defaults to 100, so no client can page the whole table in one call. detail is compact JSON carrying that event's own facts, with keys sorted so two receipts diff cleanly.

Under /v1 the same route gains the versioned conventions: limit and cursor, an {"items": [...], "next_cursor": ...} envelope, and the versioned error shape.

curl -s "https://api.engramdynamics.org/v1/audit?limit=50" \
  -H "Authorization: Bearer <your key>"

Deletion receipts

Deletions get a route of their own, because a deletion receipt is the one row a customer is entitled to go and find after the fact, and the obvious place to look for it is impossible by construction: the document base whose id you would use is exactly what the delete removed. So receipts are addressable at the workspace level.

curl -s "https://api.engramdynamics.org/audit/deletions?limit=20" \
  -H "Authorization: Bearer <your key>"

Each row's detail carries the per-tier outcome, with the same tier names as the published erasure timeline, so a receipt and the timeline read against each other line for line. Data lifecycle and deletion has that table and what each tier means.

This route is workspace-admin only, rather than any member: the listing names every document base the workspace has ever deleted, which is a workspace-wide history and not the caller's own activity.

What is not in it

Next

Exports turns this log, and your usage, into files you can hand to a reviewer or load into a pipeline.