Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion docusaurus/docs/cms/features/audit-logs.md
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,7 @@ The Audit Logs feature logs the following events:
| Entry assignee <VersionBadge version="5.56.1+" noTooltip /> | `update` |
| Entry review stage <VersionBadge version="5.56.1+" noTooltip /> | `updateEntryStage` |
| Media | `create`, `update`, `delete` |
| Login / Logout | `success`, `fail` |
| Admin Login / Logout | `success`, `error`, `autoRegistration` |
| Releases | `create`, `update`, `delete`, `trigger` |
| Release entries | `add`, `update`, `remove` |
| Release settings | `update` |
Expand All @@ -116,6 +116,8 @@ For each log item, the following information is displayed:

User events cover admin accounts, recorded as `admin-user.*`. An update records only the fields that changed, among first name, last name, email, username, preferred language, active status, and roles. No row is written when nothing changed.

Admin login events record successful logins (`admin.auth.success`), failed login attempts (`admin.auth.error`), and new accounts created via SSO auto-registration (`admin.auth.autoRegistration`). The `admin.auth.error` action captures the reason for failure (for example: `invalid_credentials`, `account_inactive`, `sso_connection_error`) and the authentication provider used. The `admin.auth.autoRegistration` action records when an SSO login creates a new admin account. Both failed login and auto-registration events are recorded with an unknown actor to protect privacy.

Password events cover a password set from the profile or by an admin on another account (`password.update`), a password reset requested and confirmed from the public login page (`password-reset.create` and `password-reset.confirm`), and an invitation accepted (`invite.accept`). The password, its hash, and reset or registration tokens are never recorded. These password reset and invitation actions happen with no admin session, so their User column shows `-`.

The Action filter also matches the legacy `user.create`, `user.update` and `user.delete` values used before this format, so old and new rows appear together.
Expand Down
Loading