Skip to main content
Applicable plans: Enterprise
The Audit Log helps enterprise admins review important administrative operation records within the organization, including operations related to organization settings, members and invitations, user groups, authentication, subscriptions and billing, models, usage configuration, IM channels, and more. Through the Audit Log, admins can trace “who performed what operation on which management object at what time, and whether the operation was successful,” useful for security investigations, permission accountability, configuration tracing, and internal compliance documentation.

Viewable Scope

The Audit Log is only visible to Admin roles in the enterprise organization. Members cannot see the Audit Log entry, nor can they query or export audit logs. The Audit Log records administrative operations from both the admin console and Open APIs, including successful operations and failed attempts. Some system-triggered events, such as invitation expiration or seat expiration, may also appear in the audit log to preserve a complete operation chain.

Content Not Recorded

The Qoder Audit Log only records administrative operation metadata and configuration change summaries — it does not record user business content. The following content will NOT appear in audit logs:
  • User Prompts
  • Model responses
  • Code snippets, Diffs, file content
  • Terminal commands and terminal output
  • IDE, CLI, or Agent execution processes
  • MCP tool call parameters
  • Tokens, API Keys, secrets, or certificate plaintext
When sensitive configurations such as secrets, Tokens, or certificates are involved, the audit log only records status changes like created, updated, deleted, or revoked, or records redacted identifiers — plaintext content is never displayed.

Currently Supported Operation Events

The following events are categorized by their location in the admin console. “Console location” indicates the page or functional area corresponding to the event; “Page operation” indicates the write operation performed by the admin in the console; “Operation event” indicates the system event identifier displayed in the audit log.

Settings

Records changes to organization basic information, organization bindings, email domains, authentication, default quotas, and other settings.

Organization Basic Settings

Domain Verification

Authentication & SAML

Default Usage Quota

Members

Records member joins, member information changes, member removals, member logins, invitations, and user group operations.

Member Management

Member Invitations

User Groups & Group Policies

Models

Records admin changes to official models and model-related management configurations on the “Models” page. These events only record model management configuration changes — they do not record model call content, Prompts, or responses.

Official Models

When supplier credentials, API Keys, secrets, or other sensitive configurations are involved, the audit log only records that the configuration was created, updated, or deleted — secret plaintext is never displayed.

Security Policies

Records organization-level security policy configuration changes, such as codebase security policies.

IM Channels

Records enabling and disabling of organization IM channel configurations.

Organization Usage

Records member usage limits, billing group usage limits, Shared Add-on Credits default limits, and usage report exports.

Subscriptions & Billing

Records enterprise subscription, seat allocation, and billing group operations.

Subscriptions

Seats

Billing Groups