Audit Logs
SecuriTLS records security-sensitive, administrative, certificate lifecycle, ACME, storage, deployment, authentication, and workspace activity so important changes and access events can be reviewed later.
Overview
Audit logs provide a historical record of significant actions performed through SecuriTLS. They help administrators understand what changed, when it changed, which resource was affected, and whether an operation succeeded or was denied.
Audit coverage focuses on operations that change security state, PKI state, access, automation, deployment state, or sensitive configuration. SecuriTLS also records important authentication, authorization, and ownership failures.
The sections below list the operations currently recorded by the audit system.
Organizations and workspaces
- Create an organization
- Delete an organization
- Switch workspaces
- Update a workspace name
- Unset a workspace
Users and invitations
- Invite a user
- Add a user to a workspace
- Edit a user or invitation role
- Delete a user
Authentication and authorization
- Successful user authentication
- Failed user authentication attempts
- Role-based authorization failures
- Requests denied because the authenticated user does not own or have access to the requested resource
- Rate-limited authentication, registration, password reset, and other protected requests
- Successful two-factor authentication
- Two-factor authentication enabled or disabled
- Use of a two-factor authentication recovery code
- SSO configuration creation and updates
- SSO enable and disable operations
- SSO configuration tests
- Verified login domain changes
Ownership and access failures are recorded for resources including certificates, credentials, devices, satellites, storage providers, storage keys, API keys, alerts, integrations, and other workspace-scoped objects.
Storage and encryption configuration
- Update the default storage provider
- Update the encryption provider associated with default storage
- Create a storage provider
- Update a storage provider
- Delete a storage provider
- Create a storage encryption key
- Delete a storage encryption key
Satellites
- Create a satellite
- Update a satellite
- Enable a satellite
- Disable a satellite
- Generate a satellite JWT
Alerts
- Acknowledge an alert
- Close an alert
API keys
- Create an API key
- Update an API key
- Delete an API key
API key secrets are displayed only when created. SecuriTLS does not provide a separate secret reveal or regeneration workflow.
Certificates and lifecycle operations
- Create a certificate or certificate authority
- Renew a certificate
- Rekey a certificate
- Reissue a certificate
- Revoke a certificate
- Delete a certificate
- Import certificates
- Migrate certificates to another storage provider
- Download private keys
- Download encrypted private keys
- Generate ACME External Account Binding credentials for a certificate authority
ACME
- Generate External Account Binding credentials for an issuing CA
- Register a new ACME account
- Create certificates through the ACME issuance workflow
ACME EAB HMAC keys are one-time-view credentials. Audit records track the generation event without requiring the secret itself to remain visible through the platform.
Credentials
- Create a credential
- Update a credential
- Reveal a credential
- Delete a credential
Devices, deployments, and validation
- Create a device
- Update a device
- Delete a device
- Attach or update a certificate attachment on a device
- Detach a certificate from a device
- Deploy a certificate attachment to a device
- Record whether a device deployment succeeded
- Run device validation
Deployment audit records can associate the deployed certificate with the deployment result so administrators can distinguish successful and failed delivery attempts.
Connection tests
SecuriTLS audits user-initiated device connection tests so administrators can review when connectivity to a device was tested and whether the test succeeded.
Connection tests may exercise stored device credentials, direct network connectivity, or satellite connectivity depending on the device configuration.
Audit record context
Audit entries may include context such as the authenticated user, workspace, request path, HTTP method, response status, request identifier, source or origin, affected resource metadata, timestamp, and operation-specific details.
Operation-specific audit data is intended to identify what was affected without requiring sensitive secrets such as private keys, passwords, tokens, EAB HMAC keys, or generated JWT values to be stored in the audit trail.
Audit coverage notes
Audit coverage focuses on security-sensitive and operationally significant actions rather than every read-only request made to the platform.
Configuration changes, access-control failures, sensitive material access, PKI lifecycle operations, device deployment actions, and other important administrative events are prioritized because they provide the most useful operational and security history.
Additional audited operations may be added as SecuriTLS gains new lifecycle, storage, deployment, security, ACME, integration, and workspace capabilities.