DocslothAudit
checking session

Audit

Audit displays real server state with a next action, not placeholder statistics.

Surface contract

Primary object: the authorized security and admin trail: timestamp, action, outcome, actor and details digest for every recorded event.

Actions

  • FilterFilters action, outcome and actor as query parameters; the control plane applies them server-side (?action=&outcome=&actor_id=) so the table and the export see the same rows.
  • ExportDownloads the filtered trail as CSV from this app’s own route, which forwards the session cookie to /v1/audit and relays any refusal; the file contains timestamp, action, outcome, actor, target, request and digest columns.
  • Configure sinkDeployment operatorThis build has no outbound audit-sink endpoint or webhook configuration; the trail is API-readable and downloadable. A future sink would be deployment configuration, not an in-app control, so the page states that instead of offering a save that cannot work.
Required states and how this surface reaches them
loading
the session probe and each list show Loading… until the control plane answers.
ready
the server’s own records render as returned; the primary object is named before its details.
empty
no mutation has been recorded yet; the trail is empty by fact, not by error.
error
the control plane’s status and detail are shown; no placeholder row replaces them.
offline
no control plane is reachable; nothing is rendered rather than invented.
permission_denied
a 403 states that the role cannot read the trail; a 401 returns to sign-in with this path.
not_configured
a download with no reachable control plane answers 503 with a problem body instead of an empty CSV.
budget_paused
a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
requires_approval
mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.

Scope: workspace membership (the trail is tenant-scoped server-side). Filters are query parameters the server applies; the CSV export forwards exactly the filters the list uses, and no entry is ever synthesized.

Audit trail

checking

Loading…

Rows come from the authenticated control plane; this page never renders placeholder records. Actions report the server's own response, including refusals.