Audit logging for secret access and changes
When something goes wrong with a credential, the first question is who touched it and when. Keel records the answer as it happens.
What is recorded
- Secrets: created, updated, deleted, revealed, an old version viewed, rolled back, imported, exported.
- Access: role changes, members removed or leaving, invitations created, accepted, or revoked, environment grants and revocations, and denied access attempts.
- Project: created, updated, deleted.
- Integrations: connected, updated, disconnected, synced, and deploy triggered.
What is never recorded
Secret values, invitation tokens, and token hashes are kept out of audit metadata by design. The log tells you what happened and who did it, without becoming a second place where secrets live.
Using the log
Owners and admins can open the audit log for a project, filter by category (secrets, access, project, integrations), and page through events. Each entry carries the actor, the target, and a timestamp. Repeated denied attempts by the same person on the same environment are de-duplicated over a short window so a retry loop does not bury everything else.
Limits
The log lives in the Keel database. There is no export to an external SIEM and no configurable retention policy yet.
Frequently asked questions
- Who can read the audit log?
- Project owners and admins.
- Does the log contain secret values?
- No. Values and tokens are excluded from audit metadata.
- Can I stream events to another system?
- Not currently. The log is available in the dashboard and through the project's audit API.
Keep reading
- Common secrets management mistakes in software developmentThe mistakes that most often lead to leaked credentials, from committed .env files to shared production keys, and what to do instead.
- What is secrets management? A practical guide for developersSecrets management is how you store, distribute, and control access to credentials such as API keys and database passwords. Here is what it covers and where to start.
- Access controlOwner, admin, member, and viewer roles, plus explicit per-environment grants.
- Version historyNumbered versions for every change, with restore to any earlier value.