Docs / Surface / audit-log
Audit Log
The Audit Log is a Standard and Pro feature; on Free and Starter the page returns a 403 upgrade prompt (code: "plan_required").
The Audit Log records administrative changes made to your Surface account — who did what, to which resource, and when. It answers questions like when did this profile's allowed types change? and who revoked that API key?
What gets recorded#
Configuration and access changes, rather than scan traffic:
- Scan profile changes — created, updated, deleted
- API key lifecycle — created, revoked, linked to a different profile
- Role and user changes — roles created or edited, roles assigned
- IP blocks and unblocks
Individual scans are not audit entries. Those live in Scan History, which keeps the scan record itself.
What each entry shows#
| Column | Meaning |
|---|---|
| Timestamp | When the change was made |
| Actor | The account the change was made under. Shown in the User column |
| Action | create, update, delete, and similar |
| Resource | The type and name of the thing that changed |
Retention#
Audit entries are kept for 90 days on every plan, independent of the retention window that applies to scan history. This is deliberate: the record of who changed what outlives the data the change affected. See Data Retention.
Related#
- Access Control — the roles and keys whose changes are recorded here
- Scan History — the scans themselves, not the configuration around them
Tendrl