scf_get_audit_log
Retrieve field-level changes from an organization's append-only audit trail, showing actor, source, and before/after values. Filter by entity, control, action, actor, source, date, or text.
Instructions
Query one organization's append-only audit trail (read — viewer role): field-level changes with actor, source and before/after values. Filter by entity, control, action, actor, source, date or text.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Page size (1–200, default 50) | |
| action | No | Filter by action: create, update or delete | |
| offset | No | Pagination offset — number of results to skip (default 0) | |
| org_id | Yes | Organization UUID — obtain from scf_list_organizations | |
| scf_id | No | Filter by SCF control ID in DOMAIN-NN format | |
| date_to | No | Include changes at or before this ISO-8601 timestamp (YYYY-MM-DDTHH:MM:SSZ) | |
| actor_id | No | Filter by actor user UUID — platform alias of changed_by_user_id | |
| date_from | No | Include changes at or after this ISO-8601 timestamp (YYYY-MM-DDTHH:MM:SSZ) | |
| entity_id | No | Filter by the changed entity's UUID | |
| request_id | No | Filter by request correlation ID — groups every change one API call made | |
| entity_type | No | Filter by exact entity type as written in the log, e.g. scoped_control, evidence_file, audit_engagement, vendor — unsure of the spelling? use search_text | |
| search_text | No | Case-insensitive search across entity_type, field_name, old_value and new_value | |
| action_source | No | Filter by origin of the change: ui, api_key, mcp or system | |
| changed_by_user_id | No | Filter by the user who made the change — obtain from scf_list_members |