DocsEnterprise
The audit log
Every security-relevant event, append-only and hash-chained so tampering is detectable, filterable in the console and exportable to your SIEM.
What is recorded
- Sign-ins and refused credentials or permissions.
- Principals created and changed, and their roles; keys created and revoked.
- Repositories indexed and deleted, feature flags changed, and the licence's state.
Each record says who, in which organisation, did what to what, with what outcome; the request's endpoint, the caller's address and the request id; and when.
Why it can be trusted
Each record carries the hash of the one before it. Altering, removing or reordering any record breaks the chain, and verification names the record where it breaks. Records are only ever appended.
Read, export and verify
terminal
bbm-atlas enterprise audit list --action 'sso.*' --since 2026-10-01T00:00:00Zbbm-atlas enterprise audit export audit-2026-10.jsonl --since 2026-10-01T00:00:00Zbbm-atlas enterprise audit verify --file audit-2026-10.jsonl # offline, anywherebbm-atlas enterprise audit verify # the store serve uses- An export is JSON Lines, ready for your SIEM, and verifies on its own, offline.
- In the console, the Audit log page filters by period, action, outcome and organisation, and a deployment administrator can verify the chain.
- An organisation's administrators read their own organisation's records; the deployment's administrators read and verify everything.
Retention
Records are kept for BBM_ATLAS_EE_AUDIT_RETENTION_DAYS days, 365 by default; 0 keeps them for ever. Pruning removes the oldest records and records that it did, so the rest of the chain still verifies from where it was cut.