Skip to content

Audit logs

Audit logs are a record of all actions taken in Oblique. They’re enabled by default and can’t be disabled. Audit logs are stored for 13 months.

When an action is taken outside Oblique through an integration, the audit event records the integration it was taken in as the author. For example, a change to an Okta integration such as importing a new user or updating user attribute lists the Okta integration as the author.

When an action is taken in Oblique using a client, in addition to recording the user that took the action as the author, the audit log records the client that was used:

TargetActionDescription
UserCREATEA user was imported.
TeamCREATEA team group was created.
TeamUPDATEThe team group’s description was updated.
TeamDELETEA team group was deleted.
TeamMemberCREATEA user was added to the team group.
TeamMemberDELETEA user was removed from the team group.
TeamOwnerCREATEA user or group was added as an owner of the team group.
TeamOwnerDELETEAn owner was removed from the team group.
GroupCREATEAn attribute-based group or reporting group was created.
GroupDELETEAn attribute-based group or reporting group was deleted.
GroupOwnerCREATEA user or group was added as an owner of an attribute-based group or reporting group.
GroupOwnerDELETEAn owner was removed from an attribute-based group or reporting group.
ResourceCREATEA resource was imported.
EntitlementCREATEAn entitlement was created.
EntitlementUPDATEAn entitlement was edited.
EntitlementDELETEAn entitlement was revoked.
RequestCREATEA request was created.
RequestUPDATEA request’s state, reviewers, or auto-apply settings changed.
RequestEventCREATEA request’s state, reviewers, or auto-apply settings changed.
AccessReviewCREATEAn access review was started.
AccessReviewUPDATEA review’s scope was confirmed, or the review was completed or re-opened.
AccessReviewDELETEA review was deleted.
AccessReviewAppCREATEAn app was added to a review’s scope.
AccessReviewAppUPDATEA review captured an app’s accounts when the scope was confirmed.
AccessReviewAppDELETEAn app was removed from a review’s scope.
AccessReviewAccountCREATEAn account was captured or manually added to an app in a review.
AccessReviewAccountDELETEAn account was removed from an app in a review.
AccessReviewDecisionUPDATEA decision was recorded, changed, or cleared for an account in a review, including any notes.
AccessReviewScreenshotCREATEA screenshot was attached to an app in a review.
AccessReviewScreenshotUPDATEA screenshot finished being read for an app in a review.
AccessReviewScreenshotDELETEA screenshot was removed from an app in a review.
AccessReviewRemediationEvidenceCREATERemediation evidence was added for an app in a review.
AccessReviewRemediationEvidenceDELETERemediation evidence was removed from an app in a review.
AccessScreenshotCREATEAn image upload for an access screenshot or remediation evidence started.
AccessScreenshotUPDATEAn image finished uploading, or Oblique finished reading it.
AccessScreenshotDELETEAn image was deleted.
IntegrationCREATEAn integration was added.
IntegrationUPDATEAn integration’s settings were updated, including approvals from Slack.
IntegrationAccountCREATEAn integration reported an account, including the user it was matched to.
IntegrationAccountUPDATEAn account’s details changed, or it was matched to or unmatched from a user.
IntegrationAccountDELETEAn integration stopped reporting an account.
ServiceAccountCREATEAn API key was created.
ServiceAccountDELETEAn API key was revoked.
AdminCREATEAn admin was added.
AdminDELETEAn admin was removed.
OwnerUPDATEThe organization owner was changed.
You must be an admin to view audit logs.

Navigate to the Logs page.

The system displays the most recent logs by default, including information about the actor, action, and target. Select Show diff to view more details, including a one-line summary of the action and a diff of the values for the affected target.

Oblique’s audit logs are a record of all actions taken in Oblique or synced to Oblique, including authorization changes. Oblique does not track when a user authenticates, fails to authenticate, or otherwise uses their access.

For Okta resources, you can see authentication events in Okta’s admin system log. From an Okta resource’s detail page, select More in the header, then View logs in Okta. Okta opens with the system log filtered to that resource.

Select Filter to narrow the events shown. You can filter by:

  • Time: today, yesterday, last 7 days, or last 30 days. By default, the last 30 days of logs are shown.
  • Author: the user, service account, or integration that performed the action
  • Client: where the action was performed from, such as the web app, an MCP client, or an integration
  • Action: Create, Update, or Delete
  • Targets: a specific user, group, team, resource, integration, or service account affected by the event
  • Target type: the type of object affected by the event, such as entitlement, request, integration, resource, service account, team member, or user attribute