Audit Events
Which API routes write an entry to the audit log, and with what. Every route that can change state (POST, PUT, PATCH, DELETE) is classified in apps/api/audit_coverage.yaml; the test suite fails when a route is missing from it or an entry names a route that no longer exists, and the known gaps list may only shrink. Values come from the vocabulary reference.
Audited routes
Snapshot says which states the entry records: the object before the change, after it, both (an update, so the entry carries a field-level diff), or none (the entry's details describe the event instead). A route listing more than one resource type records a different object on some path — a schedule occurrence that produced no run is recorded on the schedule.
| Method | Path | Resource type | Actions | Snapshot |
|---|---|---|---|---|
POST | /binary-artifacts/bulk-delete | binary_artifact | purge | both |
DELETE | /binary-artifacts/{artifact_id} | binary_artifact | purge | both |
POST | /file-repositories/ensure-default | file_repository | create | after |
POST | /file-repositories/{file_repository_id}/folders | file_repository_folder | create | after |
POST | /file-repositories/{file_repository_id}/folders/rename | file_repository_folder | rename | both |
DELETE | /file-repositories/{file_repository_id}/folders | file_repository_folder | delete | before |
POST | /files/{file_id}/move | stored_file | move | both |
POST | /audit-logs/cleanup | audit_log | prune | none |
POST | /api-tokens | personal_access_token | create | after |
DELETE | /api-tokens/by-user/{username} | personal_access_token | revoke | none |
DELETE | /api-tokens/{token_id} | personal_access_token | revoke | none |
POST | /approvals/{approval_id}/decision | approval | approve, reject | both |
POST | /config-exchange/operations | config_exchange | export, import, plan, apply | both |
POST | /devices | device | create | after |
POST | /devices/bulk/delete | device | soft_delete | before |
POST | /devices/bulk/permanent | device | permanent_delete | before |
POST | /devices/bulk/restore | device | restore | none |
DELETE | /devices/{device_id} | device | soft_delete | before |
PUT | /devices/{device_id} | device | update | both |
PATCH | /devices/{device_id}/overlay | device | annotate | both |
POST | /devices/{device_id}/duplicate | device | duplicate | after |
DELETE | /devices/{device_id}/permanent | device | permanent_delete | before |
POST | /devices/{device_id}/restore | device | restore | after |
POST | /file-repositories | file_repository | create | after |
DELETE | /file-repositories/{file_repository_id} | file_repository | delete | before |
PATCH | /file-repositories/{file_repository_id} | file_repository | update | both |
POST | /registry-credentials | registry_credential | create | after |
PATCH | /registry-credentials/{credential_id} | registry_credential | update | both |
DELETE | /registry-credentials/{credential_id} | registry_credential | delete | before |
DELETE | /images/repository | container_image | delete | before |
DELETE | /images/repository/tag | container_image | delete | before |
DELETE | /platform/images/repository | container_image | delete | before |
DELETE | /platform/images/repository/tag | container_image | delete | before |
POST | /file-repositories/{file_repository_id}/files/import | stored_file | import | after |
POST | /file-repositories/{file_repository_id}/files/upload | stored_file | upload, restore | after |
POST | /file-repositories/{file_repository_id}/set-default | file_repository | set_default | both |
DELETE | /files/{file_id} | stored_file | permanent_delete | before |
POST | /flows | flow | create | after |
DELETE | /flows/{flow_id} | flow | soft_delete | before |
PUT | /flows/{flow_id} | flow | update | both |
POST | /flows/{flow_id}/attachments | flow_attachment | create | after |
POST | /flows/{flow_id}/attachments/bulk | flow_attachment | bulk_create, create, update | after |
POST | /flows/{flow_id}/attachments/bulk-rename | flow_attachment | bulk_rename, rename | both |
DELETE | /flows/{flow_id}/attachments/folder | flow_attachment | delete | before |
DELETE | /flows/{flow_id}/attachments/{attachment_id} | flow_attachment | delete | before |
PATCH | /flows/{flow_id}/attachments/{attachment_id} | flow_attachment | update | both |
POST | /flows/{flow_id}/commit | flow | commit | none |
PATCH | /flows/{flow_id}/git | flow | link_git, clear_git, update_git, detach_git | both |
POST | /flows/{flow_id}/git/detach | flow | detach_git | both |
PATCH | /flows/{flow_id}/pin | flow | update | both |
PATCH | /flows/{flow_id}/manual-runs | flow | update | both |
DELETE | /flows/{flow_id}/permanent | flow | permanent_delete | before |
POST | /flows/{flow_id}/draft | flow | update | both |
POST | /flows/{flow_id}/duplicate | flow | duplicate | after |
POST | /flows/{flow_id}/notifications/subscriptions | flow_notification_subscription | create | after |
PATCH | /flows/{flow_id}/notifications/subscriptions/{subscription_id} | flow_notification_subscription | update | both |
DELETE | /flows/{flow_id}/notifications/subscriptions/{subscription_id} | flow_notification_subscription | delete | before |
POST | /flows/{flow_id}/push-to-git | flow | export | none |
POST | /flows/{flow_id}/restore | flow | restore | after |
POST | /flows/{flow_id}/restore/{version} | flow | restore | both |
POST | /flows/{flow_id}/revert-draft | flow | restore | both |
POST | /flows/{flow_id}/sync-from-git | flow | sync | none |
POST | /git-repositories/{repo_id}/sync | git_repository | sync | none |
POST | /platform-sync/profiles | platform_sync_profile | create | after |
PATCH | /platform-sync/profiles/{profile_id} | platform_sync_profile | update | both |
DELETE | /platform-sync/profiles/{profile_id} | platform_sync_profile | soft_delete | both |
POST | /git-repositories | git_repository | create | after |
DELETE | /git-repositories/{repo_id} | git_repository | soft_delete | before |
PATCH | /git-repositories/{repo_id} | git_repository | update | both |
POST | /hooks/{path_token} | webhook_endpoint | trigger | after |
POST | /internal/schedules/{schedule_id}/trigger | run, schedule | start | after |
PATCH | /internal/approvals/{approval_id} | approval | approve, reject, expire, cancel, update | both |
POST | /internal/runs/{run_id}/approvals | approval | request | after |
POST | /inventory/providers | inventory_provider_config | create | after |
DELETE | /inventory/providers/{provider_id} | inventory_provider_config | soft_delete | both |
PATCH | /inventory/providers/{provider_id} | inventory_provider_config | update | both |
DELETE | /inventory/providers/{provider_id}/permanent | inventory_provider_config | permanent_delete | before |
POST | /inventory/providers/{provider_id}/purge-inventory | inventory_provider_inventory | purge | both |
POST | /inventory/providers/{provider_id}/restore | inventory_provider_config | restore | both |
POST | /inventory/providers/{provider_id}/sync | inventory_provider_config | sync | after |
POST | /inventory/providers/{provider_id}/discover | inventory_provider_config | discover | both |
GET | /inventory/object-types | inventory_provider_config | discover | both |
POST | /notifications/destinations | notification_destination | create | after |
DELETE | /notifications/destinations/{destination_id} | notification_destination | soft_delete | before |
PATCH | /notifications/destinations/{destination_id} | notification_destination | update | both |
POST | /notifications/destinations/{destination_id}/duplicate | notification_destination | duplicate | after |
DELETE | /notifications/destinations/{destination_id}/permanent | notification_destination | permanent_delete | before |
POST | /notifications/destinations/{destination_id}/restore | notification_destination | restore | both |
POST | /notifications/destinations/{destination_id}/test | notification_destination | test | after |
POST | /orgs | organization | create | after |
DELETE | /orgs/{org_ref} | organization | delete | before |
PATCH | /orgs/{org_ref} | organization | update | both |
POST | /orgs/{org_ref}/idp-mappings | org_idp_mapping | create | after |
DELETE | /orgs/{org_ref}/idp-mappings/{mapping_id} | org_idp_mapping | delete | before |
PATCH | /orgs/{org_ref}/idp-mappings/{mapping_id} | org_idp_mapping | update | after |
POST | /orgs/{org_ref}/members | org_membership | create | after |
DELETE | /orgs/{org_ref}/members/{user_id} | org_membership | delete | before |
PATCH | /orgs/{org_ref}/members/{user_id} | org_membership | update | both |
POST | /platform-sync/profiles/{profile_id}/apply | platform_sync_profile | apply | none |
POST | /platform-sync/profiles/{profile_id}/conflicts/{change_id}/resolve | platform_sync_plan | resolve | none |
POST | /platform-sync/profiles/{profile_id}/destructive-authorizations | platform_sync_destructive_authorization | create | none |
POST | /platform-sync/profiles/{profile_id}/destructive-authorizations/{authorization_id}/revoke | platform_sync_destructive_authorization | revoke | none |
POST | /platform-sync/profiles/{profile_id}/export | platform_sync_profile | export | none |
POST | /platform-sync/profiles/{profile_id}/plan | platform_sync_profile | plan | none |
POST | /runs | run | start | after |
DELETE | /runs/{run_id} | run | soft_delete | before |
PATCH | /runs/{run_id} | run | update | both |
POST | /runs/{run_id}/approvals/{approval_id}/decision | approval | approve, reject | both |
POST | /runs/{run_id}/cancel | run | cancel | both |
POST | /runs/{run_id}/pause | run | pause | both |
DELETE | /runs/{run_id}/permanent | run | permanent_delete | before |
POST | /runs/{run_id}/restore | run | restore | after |
POST | /runs/{run_id}/resume | run | resume | both |
POST | /schedules | schedule | create | after |
DELETE | /schedules/{schedule_id} | schedule | soft_delete | before |
PATCH | /schedules/{schedule_id} | schedule | update | both |
DELETE | /schedules/{schedule_id}/permanent | schedule | permanent_delete | before |
POST | /schedules/{schedule_id}/restore | schedule | restore | after |
POST | /schedules/{schedule_id}/run | run | start | after |
POST | /secrets | secret | create | after |
DELETE | /secrets/{secret_id} | secret | delete | before |
PATCH | /secrets/{secret_id} | secret | update | both |
DELETE | /settings/permissions/actions/override | permission_action_override | delete | before |
DELETE | /settings/permissions/override | permission_override | delete | before |
PUT | /settings/permissions/actions/override | permission_action_override | create, update | both |
PUT | /settings/permissions/override | permission_override | create, update | both |
POST | /settings/secrets-backends | secret_backend | create | after |
DELETE | /settings/secrets-backends/{backend_id} | secret_backend | delete | before |
PATCH | /settings/secrets-backends/{backend_id} | secret_backend | update | both |
POST | /sites | site | create | after |
POST | /sites/bulk/delete | site | soft_delete | before |
POST | /sites/bulk/permanent | site | permanent_delete | before |
POST | /sites/bulk/restore | site | restore | none |
DELETE | /sites/{site_id} | site | soft_delete | before |
PATCH | /sites/{site_id} | site | update | both |
POST | /sites/{site_id}/duplicate | site | duplicate | after |
DELETE | /sites/{site_id}/permanent | site | permanent_delete | before |
POST | /sites/{site_id}/restore | site | restore | after |
DELETE | /tf-states/{name} | tf_state | delete | before |
POST | /tf-states/{name}/force-unlock | tf_state | unlock | after |
DELETE | /tf-states/{name}/lock | tf_state | unlock | after |
POST | /tf-states/{name}/rollback | tf_state | rollback | both |
POST | /tf-states/{name}/import | tf_state | import | after |
POST | /tf-states/{name}/state | tf_state | update | after |
GET | /tf-states/{name}/versions/{version}/content | tf_state | export | after |
POST | /variables | variable | create | after |
DELETE | /variables/{variable_id} | variable | soft_delete | before |
PATCH | /variables/{variable_id} | variable | update | both |
DELETE | /variables/{variable_id}/permanent | variable | permanent_delete | before |
POST | /variables/{variable_id}/restore | variable | restore | after |
POST | /webhooks | webhook_endpoint | create | after |
DELETE | /webhooks/{webhook_id} | webhook_endpoint | soft_delete | before |
PATCH | /webhooks/{webhook_id} | webhook_endpoint | update | both |
DELETE | /webhooks/{webhook_id}/permanent | webhook_endpoint | permanent_delete | before |
POST | /webhooks/{webhook_id}/restore | webhook_endpoint | restore | after |
POST | /webhooks/{webhook_id}/rotate-secret | webhook_endpoint | rotate | both |
Exempt routes
Routes that change nothing durable, or whose effects another record already captures (run events, monitor samples). Each carries its reason.
| Method | Path | Reason |
|---|---|---|
POST | /api/v1/monitor-samples/batch | high-volume worker telemetry; the monitor samples themselves are the record |
POST | /api/v1/monitors | worker monitor lifecycle; run_events and the monitor rows are the record |
PATCH | /api/v1/monitors/{monitor_db_id} | worker monitor lifecycle; run_events and the monitor rows are the record |
POST | /api/v1/monitors/finalize-for-run/{run_id} | worker monitor lifecycle; run_events and the monitor rows are the record |
POST | /auth/bff/ticket | short-lived stream ticket; the stream's target resource is audited on its own routes |
POST | /binary-artifacts/bulk-download | read-only download (POST carries the id list) |
POST | /config-exchange/operations/{correlation_id}/cancel | always answers 409; nothing changes |
POST | /file-repositories/{file_repository_id}/test-connection | connectivity probe; only last_connected_at bookkeeping changes |
POST | /registry-credentials/{credential_id}/test | login probe; only last_connected_at bookkeeping changes |
POST | /files/{file_id}/device-download-url | read-only presigned URL issuance |
POST | /files/{file_id}/download-url | read-only presigned URL issuance |
POST | /flows/{flow_id}/interface/options | read-only query carried in a POST body |
POST | /flows/{flow_id}/interface/preview-resolve | read-only dry run |
POST | /flows/{flow_id}/interface/validate | read-only validation |
POST | /flows/{flow_id}/validate | read-only validation |
POST | /git-repositories/{repo_id}/test-connection | connectivity probe; only last_connected_at bookkeeping changes |
POST | /internal/maintenance/tick | runs the maintenance jobs; each job audits its own effects |
PATCH | /internal/runs/{run_id} | worker run lifecycle; run_events is the record |
POST | /internal/runs | engine-spawned subflow run; the parent run's start entry and run_events are the record |
POST | /internal/runs/{run_id}/artifacts | worker run lifecycle; run_events is the record |
POST | /internal/runs/{run_id}/artifacts/upload | worker run lifecycle; run_events is the record |
POST | /internal/runs/{run_id}/assign-shared-worker | worker placement bookkeeping; run_events is the record |
POST | /internal/runs/{run_id}/cancel | engine-initiated cancellation cascade; run_events is the record (user cancellations are audited on POST /runs/{run_id}/cancel) |
POST | /internal/runs/{run_id}/events | worker run lifecycle; run_events is the record |
PUT | /internal/runs/{run_id}/run-vars | worker run lifecycle; run_events is the record |
POST | /internal/runs/{run_id}/step-runs | worker run lifecycle; run_events is the record |
POST | /internal/runs/{run_id}/tf-state-access | issues a step's short-lived token for one state; what the step does with it is audited on the state routes, naming the run |
DELETE | /internal/runs/{run_id}/tf-state-access/{token_id} | revokes a step's short-lived token early; the run's end revokes it anyway |
POST | /internal/runs/{run_id}/registry-access | issues a container step's short-lived registry token; what the step pulls or caches is in its run events |
DELETE | /internal/runs/{run_id}/registry-access/{token_id} | revokes a step's short-lived registry token early; the run's end revokes it anyway |
PATCH | /internal/step-runs/{step_run_id} | worker run lifecycle; run_events is the record |
POST | /internal/runtime/env-keys | in-process registry; nothing durable changes |
DELETE | /internal/runtime/env-keys/{worker_id} | in-process registry; nothing durable changes |
POST | /internal/workers/heartbeat | liveness only; nothing durable changes |
POST | /inventory/providers/{provider_id}/test-connection | connectivity probe; only last_tested_* bookkeeping changes |
POST | /tf-states/{name}/lock | transient coordination held for one plan or apply; the version it writes and any force unlock are audited |
POST | /notifications/destinations/test-config | read-only probe of a submitted config |
POST | /schedules/validate-cron | read-only validation |
POST | /secrets/{secret_id}/duplicate | not implemented; answers 501 |
POST | /settings/secrets-backends/{backend_id}/test | connectivity probe; nothing changes |
POST | /variable-contexts | read-only query carried in a POST body |
POST | /variable-contexts/validate | read-only validation |
POST | /webhooks/{webhook_id}/test | read-only validation |
Known gaps
Routes that change state and do not record an entry yet. Each names the change that closes it; this list only shrinks.
| Method | Path | Closing change |
|---|