How to View IAM Audit Logs
Go to Audit & Compliance → IAM Audit LogsHow to Filter IAM Audit Logs
Use the filter panel to narrow down results:- Search: Filter by user email or resource
- Status: Show only successful or failed operations
- Date Range: Specify start and end dates
- User Email: Filter by specific user
- Action: Filter by action type (e.g.,
role_assign,user_invite) - Resource: Filter by resource type (e.g.,
user,role,group)
How to View Log Details
Click on any log entry to expand and see:- Full timestamp
- User who performed the action
- Action type and target resource
- Success or failure status
- Detailed changes (before/after values when applicable)
- IP address and user agent
Common IAM Actions
User Management:user_invite- User invitation sentuser_remove- User removed from organizationuser_update- User details updated
role_create- New role createdrole_update- Role permissions modifiedrole_delete- Role deletedrole_assign- Role assigned to user or grouprole_revoke- Role removed from user or group
group_create- New group createdgroup_update- Group details modifiedgroup_delete- Group deletedgroup_member_add- User added to groupgroup_member_remove- User removed from group
permission_check- Permission verification (logged when access is denied)
Troubleshooting
Cannot find a specific IAM change
Cannot find a specific IAM change
- Expand the date range - the change may be older than expected
- Search by the user’s email who made the change
- Filter by resource type (user, role, group)
- Clear all filters and browse chronologically
Permission denied entries appearing
Permission denied entries appearing
permission_check entries with failed status indicate users attempted actions they don’t have permission for. Review if:- The user needs additional roles
- The role is missing required permissions
Cannot see IAM Audit Logs
Cannot see IAM Audit Logs
You need the
iam:tenant:iam:audit:read permission to view IAM audit logs. Contact your administrator.FAQ
What's the difference between Audit Logs and IAM Audit Logs?
What's the difference between Audit Logs and IAM Audit Logs?
Audit Logs track all system operations (API calls, cluster changes, deployments). IAM Audit Logs specifically track identity and access changes (users, roles, groups, permissions).
Can I see who assigned a role to a user?
Can I see who assigned a role to a user?
Yes. Filter by action
role_assign and search for the target user’s email. The log shows who performed the assignment.Are permission denials logged?
Are permission denials logged?
Yes. When a user attempts an action without permission, it’s logged as
permission_check with failed status.Can I see what changed in a role update?
Can I see what changed in a role update?
Yes. Click on the log entry to expand details. For role updates, you can see which permissions were added or removed.
How long are IAM audit logs retained?
How long are IAM audit logs retained?
Retention period depends on your plan. Contact support for specific details or extended retention needs.