Project-level vs. organization-level
- The project Audit Log (under the Observability group) covers activity scoped to that project: Policy Set lifecycle transitions, agent changes, and flagged/blocked requests.
- The organization Audit Log (under Organization Settings) aggregates events across every project in the org, and supports CSV export for compliance reporting.
What’s recorded
Each entry includes a timestamp, the actor (user or system), the action taken, and the affected resource (Policy Set, Agent, Use Case, Access Key, Control, or Criterion). Entries tied to a Rule match also link to the underlying request trace.Violations
Policy Set Rule matches that result in ablock, flag, or redact action are surfaced in the project’s Violations view, filterable by severity and Policy Set, so you can quickly spot which rules are triggering most often.