Audit
Audit displays real server state with a next action, not placeholder statistics.
Surface contract
Primary object: the authorized security and admin trail: timestamp, action, outcome, actor and details digest for every recorded event.
Actions
- FilterFilters action, outcome and actor as query parameters; the control plane applies them server-side (?action=&outcome=&actor_id=) so the table and the export see the same rows.
- ExportDownloads the filtered trail as CSV from this app’s own route, which forwards the session cookie to /v1/audit and relays any refusal; the file contains timestamp, action, outcome, actor, target, request and digest columns.
- Configure sinkDeployment operatorThis build has no outbound audit-sink endpoint or webhook configuration; the trail is API-readable and downloadable. A future sink would be deployment configuration, not an in-app control, so the page states that instead of offering a save that cannot work.
Required states and how this surface reaches them
- loading
- the session probe and each list show Loading… until the control plane answers.
- ready
- the server’s own records render as returned; the primary object is named before its details.
- empty
- no mutation has been recorded yet; the trail is empty by fact, not by error.
- error
- the control plane’s status and detail are shown; no placeholder row replaces them.
- offline
- no control plane is reachable; nothing is rendered rather than invented.
- permission_denied
- a 403 states that the role cannot read the trail; a 401 returns to sign-in with this path.
- not_configured
- a download with no reachable control plane answers 503 with a problem body instead of an empty CSV.
- budget_paused
- a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
- requires_approval
- mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.
Scope: workspace membership (the trail is tenant-scoped server-side). Filters are query parameters the server applies; the CSV export forwards exactly the filters the list uses, and no entry is ever synthesized.
Audit trail
checkingLoading…
Rows come from the authenticated control plane; this page never renders placeholder records. Actions report the server's own response, including refusals.