Audit log
The Audit log is an immutable, tamper-evident record of every change made in your workspace. Every meaningful mutation — a flag toggled, a key rotated, a member invited — is written here and cannot be edited or deleted.
What gets logged
Changes across every resource are captured, including:
- Flags — create, edit, enable, disable, archive, restore, delete.
- Segments — create, edit, delete.
- API keys — create, rotate, revoke.
- Members & invites — invite, accept, role change, suspend.
- Workspace & webhooks — workspace settings updates, webhook registrations, and updates.
What each entry records
| Field | Meaning |
|---|---|
| Resource | The type and key of the thing that changed. |
| Action | What happened — create, edit, on, off, revoke, … |
| Summary | A human-readable description of the change. |
| Diff | The specific fields that were added, removed or changed. |
| Actor | The user who made the change, and their IP address. |
| Timestamp | When it happened. |
| Hash | A cryptographic hash linking this entry to the previous one. |
Filtering
The log can be filtered by resource type, by action, and by free-text search across summaries, actors and resource keys — useful when you need to answer "who changed this flag, and when?".
The hash chain
Each entry stores a hash computed from its own contents and the hash of the entry before it. This forms a chain: altering or removing any past entry would break every hash after it.
Verifying integrity
Admins and owners can click Verify chain. RestFlags recomputes every hash from the first entry to the last and confirms the chain is unbroken:
- Chain verified — every entry is intact and in order. The log is trustworthy.
- Broken — an entry has been tampered with; the verifier points to where the chain first fails.
This gives you a defensible, verifiable history for security reviews.
Using the audit log
- Incident response — reconstruct exactly what changed and who changed it.
- Debugging — when a flag behaves unexpectedly, the log shows its recent edits. Each flag's detail page also has an activity view scoped to just that flag.