Skip to main content
Glama
orchestra-hq

Orchestra MCP Server

Official
by orchestra-hq

List audit events

list_audit_events
Read-only

Retrieve audit trail events for a workspace, newest first, showing who did what to which resource and what changed. Filter by time window, actor, action, or resource.

Instructions

List the audit trail for the workspace the credential resolves to, newest first: who did what, to which resource, and what changed.

occurred_after is required and sets how far back the trail is read; every other filter narrows within that window.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pageNoPage number. Must be greater than or equal to 1.
actionNoFilter by action. Comma-separated values are supported. One of: ACCOUNT_CREATED, ACCOUNT_DELETED, ACCOUNT_SETTINGS_UPDATED, ACCOUNT_UPDATED, AGENT_CREATED, AGENT_DELETED, AGENT_UPDATED, API_KEY_ROTATED, ASSET_CREATED, ASSET_DELETED, ASSET_DEPENDENCIES_CREATED, ASSET_UPDATED, ENVIRONMENT_CREATED, ENV...
actor_idNoOnly events performed by this actor, matched on the recorded actor id.
page_sizeNoNumber of items per page. Defaults to 25; maximum 100.
resource_idNoOnly events on this resource, by its id or YAML name.
resource_typeNoFilter by the type of resource acted on. Comma-separated values are supported. One of: ACCOUNT, AGENT, API_KEY, ASSET, ENVIRONMENT, GIT_CONNECTION, GROUP, INCIDENT, INTEGRATION_CONNECTION, INTEGRATION_STATE, INVITE, IP_RESTRICTIONS, MONITOR, ORGANISATION, PIPELINE, PIPELINE_RUN, PRODUCT, SKILL, TASK...
occurred_afterYesOnly events at or after this time, as an ISO 8601 timestamp (e.g. 2026-09-01T00:00:00Z). Required.
occurred_beforeNoOnly events at or before this time, as an ISO 8601 timestamp.
X-Orchestra-Account-IdNoAct on this account rather than the one the credential resolves to. Omit it to use the credential's own account. An API key is issued to a single account, so it may only name that account; an OAuth token may name any account its grant covers.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

readOnlyHint=true already declares the safety profile, and the description adds useful context beyond it: results are workspace-scoped to the credential and returned newest-first, and the required timestamp establishes the read window rather than the query being open-ended. It does not mention pagination behavior or result volume, which keeps it short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, no filler. The scope and ordering lead, and the parameter-interaction rule follows in the second sentence where it is most actionable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists so return values need no explanation, and all nine parameters are schema-documented. The description supplies scope, ordering, and filter-window semantics, but omits any pointer to sibling tools or a note on how the credential/account-id header interacts with the workspace scoping it mentions.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description earns above baseline by explaining the semantic relationship between parameters - occurred_after defines the window and all other filters narrow within it, i.e. conjunctive filtering - which an agent cannot infer from the per-field descriptions alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (list the audit trail) plus scope ('for the workspace the credential resolves to'), ordering ('newest first'), and payload content ('who did what, to which resource, and what changed'). An agent can distinguish this from siblings like list_incident_events without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explains the mechanics of use: 'occurred_after' is required and sets the read window, while every other filter narrows within it. That is clear operating context, but the description never names an alternative tool or a when-not condition against siblings such as list_incident_events.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.