Enterprise feature. Audit Logs are only available to workspaces on the
Enterprise plan.
Accessing Audit Logs
Audit Logs are available to workspace admins only. Navigate to: Admin > People & Security > Audit Logs The UI provides full-text search, time-range filtering, and CSV export.Accessing the Audit Logs viewer itself generates an
audit_log.viewed event.Log Entry Structure
Each event contains the following fields:Actor Types
For
agent.executed and tool.executed events, the actor reflects the
identity that initiated the action (user or API key). Whether the action was
AI-driven is captured in the event’s metadata.actor_type,
metadata.initiating_user_id, and metadata.initiating_user_email fields.Export and SIEM Integration
Audit Logs can be exported as CSV from the admin UI. Continuous streaming to a SIEM is supported for log stream destinations such as Datadog, Splunk, AWS S3, GCP GCS, and any custom HTTPS endpoint.IP Allowlist
If your SIEM or log stream endpoint restricts inbound traffic by IP, allowlist the following addresses. WorkOS delivery IPs (used to deliver audit log events to your log stream endpoint):Related
- See the Events Reference for the full list of emitted events.
- Single Sign-On (SSO)
- Users and Groups Provisioning
- Access Controls and Permissions