audit_log
Query a tamper-evident log of every secret read, write, or delete to trace who accessed a key and when. Filter by key, agent, or action to build an access timeline.
Instructions
[audit] Query the q-ring audit log — a tamper-evident record of every read/write/delete touching a secret. Use to investigate 'who accessed KEY recently?' or to feed an agent the access timeline for a specific credential; prefer detect_anomalies for automated unusual-pattern detection and health_check for decay-state-plus-anomalies in one call. Read-only. Returns one line per event in chronological order, formatted timestamp | action | key | [scope] | env:NAME | detail. Returns 'No audit events found' when the filter matches nothing.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| key | No | Limit to events touching this exact key. Omit for the full log. | |
| agent | No | Limit to events stamped with this agent label (clientInfo name@version). Omit for all agents. | |
| limit | No | Maximum events to return, newest first. Defaults to 20. Increase for deeper investigations. | |
| action | No | Limit to a single action verb (e.g. 'read' to see only reads). Omit for all actions. |