Audit log entries are read-only and cannot be modified or deleted.
Captured actions
Audit logs capture actions in these categories:- Credentials — connect, disconnect, rotate
- Triggers — create, update, delete, activate, deactivate
- Agents — install, uninstall, publish
- Integrations — create, update, publish, delete
- Members — invite, remove, role change
- API keys — create, delete
Narrowing the timeline
Three controls sit above the log list: an Event type dropdown, a Filters menu, and the search box.Event type
The timeline merges two streams. Pick which one you are looking at:Filters
Filters opens a menu of values for the stream you are on, and reads Filters (active) while one is applied.- On User actions, filter by Method:
POST,PATCH,PUT, orDELETE. - On Security events, filter by Reason — the reason code Guild recorded with the decision.
Searching and filtering logs
The search box supports field-scoped tokens so you can filter logs to specific operations, decisions, actors, and timeframes. Type a token asfield:value in the search box, and it parses into a typed filter.
Words that are not field-scoped tokens fall through as a free-text query that searches all fields.
Each active token renders as a removable chip below the search box. Click the X on a chip to clear that filter.
A
source: token takes precedence over the Event type dropdown, so source:security narrows the timeline to security events whatever the dropdown reads. Some tokens imply a stream: operation: and decision: are security-only, actor: and view: are user-action-only, and each pins the timeline to its own stream.
Exporting logs
Click Export in the Audit Logs view to download a CSV of the currently filtered log entries.Related records
The audit log covers administrative actions. Two other records complete the picture of what agents did and at what cost:- The session event log records every LLM call, tool invocation, sub-task spawn, error, and lifecycle transition inside each session, including who interrupted a session and when.
- Insights attributes token usage and spend to each workspace, agent, user, provider, and model.