Audit Log
hxEASM has a dedicated append-only Audit Log for significant user and administrator actions.
The Audit Log answers:
- who performed the action
- when it happened
- which action and event type occurred
- which resource/entity was affected
- what changed
- which organization was involved, when applicable
Audit Log is separate from Exposure Changes and Asset History. Exposure Changes describe attack-surface and security state changes. Asset History describes what happened to one specific Asset over time. Audit Log describes user/admin actions and configuration changes.
Ordinary GET requests and background reads are not audited.
Storage
Audit events are stored in the main PostgreSQL database in audit_logs.
The table is append-only through normal application APIs. hxEASM does not expose update or delete Audit Log endpoints.
Audit rows include:
- actor user ID
- actor username snapshot
- actor role snapshot
- organization ID
- action
- event type
- resource type and ID
- old values
- new values
- metadata
- IP address
- User-Agent
- timestamp
Audit rows may grow over time. Retention, partitioning, SIEM export, and immutable external storage are future operational options and are not implemented in this release.
Actions and Event Types
action is a broad category, such as:
createupdatedeletestatus_changecriticality_changeapprovedisableenablerole_changepermission_changesettings_change
event_type is a stable specific identifier, such as:
asset.created.manualasset.lifecycle.updatedasset.criticality.updatedasset.bulk_approvedvulnerability.created.manualvulnerability.status_changedvulnerability.has_exploit.changedscope.createdscope.updatedscope.deletedscope.approvedscan_profile.createdscan_profile.updatedscan_profile.deletedscan_settings.auto_approve_discovered_assets.changedplugin.settings.updateduser.role_changeduser.organizations_changed2fa.settings_changedapi_key.createdapi_key.revokednotification.settings.updated
Audited Events
The current implementation records meaningful user-driven mutations for:
- manual Asset creation
- Asset lifecycle changes
- Asset criticality changes
- bulk Asset approval
- manual vulnerability creation
- vulnerability status changes
- vulnerability exploit-flag changes
- Scope create/update/delete/approve/reject
- custom scan profile create/update/delete
- global scan setting changes
- plugin settings updates
- user approval, role, status, and organization-assignment changes through existing auth audit writes
- global 2FA policy updates
- user 2FA enable/disable and recovery-code regeneration through existing auth audit writes
- API key creation/revocation without storing key material
- notification settings updates
- vulnerability comment creation and update
Old and New Values
Update events store minimal diffs where practical.
Example:
{
"old_values": { "status": "new" },
"new_values": { "status": "active", "close_reason": null }
}
The Audit Log does not store entire entity snapshots when only a small field changed.
Secret Redaction
Audit records never intentionally store secrets.
Keys containing sensitive terms are redacted before insertion, including:
- password
- secret
- token
- API key
- Authorization
- JWT
- OTP / TOTP
- recovery code
Plugin and notification settings are audited through the same redaction path.
Vulnerability discussion audit entries store safe metadata and visibility/mention diffs only. Full comment bodies are not copied into audit rows.
API
Admin-only endpoint:
GET /api/v1/admin/audit
Supported filters:
user_idactionevent_typeresource_typeresource_idorganization_idfromtopagepage_size
Default page size is 50. Maximum page size is 200.
Results are sorted newest first.
UI
The Audit Log is available in:
Settings -> Administration -> Audit Log
Only administrators can view it.
Limitations
- Audit logging is best-effort for most domain mutations.
- Some older auth and 2FA events were written by legacy audit helpers and may have less detailed old/new values.
- There is no retention policy in this release.
- There is no SIEM export in this release.
- There is no tamper-evident hash chain in this release.