Audit Trail
Every credential access, share, revocation, and policy check is recorded in the encrypted audit log. Entries are append-only and cannot be modified.Logging
logAction(vault, input)
Record an audit entry. Called automatically by passport operations, but can also be called directly.
Fields:
passportId, action, actor, and optional platform, details, metadata.Promise<AuditEntry>
Audit Actions
created | viewed | shared | modified | revoked | renewed | accessed | policy-checked | detected | exported | imported
Querying
getAuditLog(vault, passportId?, filters?)
Retrieve audit entries, optionally filtered by passport and additional criteria.
searchAuditLog(vault, searchTerm, passportId?)
Full-text search across audit entry details and metadata.
getRecentActivity(vault, limit?)
Most recent audit entries across all passports.
getAccessHistory(vault, passportId)
All accessed entries for a specific passport.