# Audit log

> Everything people and keys did in your organization, read by your security system.

The console's **Audit log** — who made an agent, published it, made or rotated a key, changed a
setting, and everything your API keys did — can be read through the API, so your security system
keeps its own copy.

```sh
curl https://api.aigently.ai/v1/audit-events \
  -H "Authorization: Bearer $AIGENTLY_API_KEY"
```

## The key it needs

Make a **live** key with **Read the audit log** (`audit:read`) that reaches **every project**. The
trail is about the whole organization, so a key limited to some projects or agents is refused, and
a test key reads none of it. Like every permission that reaches this far, it is ticked on its own.

## Keeping a copy

Events come oldest first. Each has the action, who did it — a `person`, an `api_key`, or the
`platform` itself, such as when your retention period deleted conversations — what it was done to,
and the details the action recorded. `names` says what the ids in it are called today.

Keep the last page's `next_cursor`, and ask again later with it for what was done since: it comes
back on the last page too. An event from the last minute waits for the next read, so nothing done
while you were reading lands behind your cursor. `action` narrows the list, and is repeatable.

Events are kept 365 days.
