anoman
Sign InGet API Key
Documentation home

Audit log

An append-only record of every security-relevant change on your account — for SOC 2 evidence, incident review, and SIEM export.

A tamper-evident event trail

Anoman keeps an append-only audit log (the audit_events store) of security-relevant mutations. Events are only ever added — never edited or deleted — so the log stands up as SOC 2 evidence.

Each event carries the actor, the action, the target it affected, structured metadata, the source IP, and a timestamp.

Security-relevant mutations

The log captures the changes an auditor cares about, including:

  • API key create and revoke;
  • policy and guardrail-config changes;
  • billing credits and adjustments;
  • member and role changes;
  • pricing updates and MCP tool-policy changes.

Read-only actions and completion traffic are not in the audit log — those live in your request records. The audit log is only for mutations.

List and export

Use GET /anoman/v1/audit/events for a cursor-paginated list (filterable by event type) and GET /anoman/v1/audit/events/export to stream the whole log as NDJSON for your SIEM or an evidence packet.

List

# Cursor-paginated list, filterable by event type
curl "https://api.anoman.io/anoman/v1/audit/events?action=api_key.revoke&limit=50" \
  -H "Authorization: Bearer anm-sk-..."

Export

# Stream the whole log as NDJSON for your SIEM / evidence packet
curl "https://api.anoman.io/anoman/v1/audit/events/export" \
  -H "Authorization: Bearer anm-sk-..." > audit-events.ndjson

Event

{
  "id": "9f2c1e4a-8b3d-4c7a-9f10-2e5b6a1c8d40",
  "actor_type": "user",
  "actor_display": "[email protected]",
  "action": "api_key.revoke",
  "target_type": "api_key",
  "target_id": "anm-sk-ab",
  "metadata": { "reason": "rotation" },
  "ip_address": "203.0.113.7",
  "created_at": "2026-08-13T10:00:00Z"
}

Related: Guardrail-config changes recorded here are configured on the Guardrails page.

Prove what changed

Open the Audit Log to filter events and export NDJSON evidence.

On this page