Overview
Describes how to use the Audit Trail feature to track/debug/investigate changes to your resources in your Harness accounts.
An audit trail is a chronological record of all key actions performed within the system. It shows who did what, when, and where, helping you track changes and activities in your Harness account.
Audit trails are automatically generated and cannot be altered, keeping the information accurate and reliable. This information can be used during compliance or to help identify and resolve issues more quickly.
Before you begin
Viewing the audit trail
To view the audit trail at the account scope (for organization scope events, go to the Organization Settings), follow these steps:
In Harness, go to Account Settings.
Navigate to the Security and Governance section, then click Audit Trail.
The Audit Trail page opens, showing audit logs from the past 7 days by default.
Each record logs an activity that happens within the system. These records may take a few minutes to appear in the Audit Trail. If you still can't see an event, try refreshing your browser.
Filter by date and time
Limit the audit events displayed to a specific time range, from 1 day up to 2 years. Use the date picker to select the exact start and end dates, including the time of day.
Audit trail types
By default, all audit events are displayed. You can refine the records using the following filters:
Exclude Login Events: Hides authentication-related events, such as successful or failed logins, 2FA, and so on from the records.
Exclude System Events: Hides events generated by the system.
Add a filter
To add a filter, perform the following steps:
In Account Audit Trail, click the filter icon.
In the New Filter settings, select filters to refine audit events. Narrow the viewable events by adding filters and selecting:
User
Organization
Project
Resource Type
Resource Identifier
Action
In Filter Name, enter a name for your filter.
For Who can view and edit the filter?, select Only me or Everyone based on the visibility you want to set for this filter.
Select Save to create a filter.
Select Apply to view the audit events as per the filter you just created.
By default, the events of the last 7 days are returned for the filter. To view more results, you can select the date range accordingly.
Audit trail data fields
The data fields capture the information for each audit event, including the user, action, time, and affected resources.
Time: The date and time when the activity occurred.
User: The user who performed the action (typically shown as an email ID or username).
Action: The action that was performed (created, updated, deleted and so on).
Resource: The Harness entity that was affected by the action.
Organization: The organization name corresponding to the affected entity, if applicable.
Project: The project name corresponding to the affected entity, if applicable.
Module: The module corresponding to the affected entity (pipeline, Platform and so on).
Event Summary: A detailed summary of the event, highlighting the changes made, along with the corresponding YAML differences.
Audit trail for events
Audit trail are stored for up to 2 years. If you need to retain them for a longer period, you can use audit log streaming to export logs externally.
Audit logs capture key activities performed in your account. For example, when a new user is added, an audit log records the action (created, updated, revoked, etc.) along with relevant user details.
Module categories and resources
Platform Core
ORGANIZATIONPROJECTUSERUSER_GROUPROLEROLE_ASSIGNMENTPERMISSIONRESOURCE_GROUPSERVICE_ACCOUNTAPI_KEYTOKEN
Core platform entities used to manage accounts, projects, users, access control, and authentication across Harness.
Continuous Delivery
SERVICEENVIRONMENTENVIRONMENT_GROUPPIPELINETRIGGERTEMPLATEINPUT_SETDEPLOYMENT_FREEZEDB_SCHEMADB_INSTANCE
Resources used to define, configure, and execute application and database deployments.
GitOps
GITOPS_REPOSITORYGITOPS_CLUSTERGITOPS_CREDENTIAL_TEMPLATEGITOPS_REPOSITORY_CERTIFICATEGITOPS_GNUPG_KEYGITOPS_AGENTGITOPS_PROJECT_MAPPINGGITOPS_APPLICATIONGITOPS_APPLICATION_SETGITOPS_ARGOPROJECT
GitOps resources for managing clusters and applications using Git as the source of truth.
Delegates
DELEGATEDELEGATE_GROUPSDELEGATE_CONFIGURATIONDELEGATE_TOKEN
Delegates enable secure connectivity between Harness and customer infrastructure to execute tasks.
Secrets Management
SECRETCERTIFICATE
Secure storage and management of sensitive values such as secrets and certificates used by pipelines and services.
Connectors
CONNECTOR
Configurations that allow Harness to integrate with external systems such as cloud providers, Git, and artifact registries.
Dashboards
DASHBOARDDASHBOARD_FOLDER
Visual dashboards and folders used to organize and display insights and reports across modules.
Governance
GOVERNANCE_POLICYGOVERNANCE_POLICY_SET
Policies and policy sets used to enforce standards, compliance, and guardrails across the platform.
File Store
FILEVARIABLE
Files and variables stored in Harness and referenced during pipeline execution and configuration.
Platform Settings
SETTINGNG_LOGIN_SETTINGSNG_ACCOUNT_DETAILSSMTPIP_ALLOWLIST_CONFIGSTREAMING_DESTINATIONBRANDING_SETTINGSBRANDING_ASSETBANNERDATA_SINK
Account-level and platform-wide settings that control security, notifications, branding, and integrations.
Resilience Testing (Chaos Engineering)
CHAOS_HUBCHAOS_INFRASTRUCTURECHAOS_EXPERIMENTCHAOS_GAMEDAYCHAOS_PROBECHAOS_SECURITY_GOVERNANCECHAOS_IMAGE_REGISTRYDR_TEST
Resources used to design, run, and govern chaos experiments to validate system resilience.
Security Testing Orchestration
STO_TARGETSTO_EXEMPTIONSTO_OVERRIDETICKET
Security testing targets, exceptions, overrides, and ticketing artifacts for managing security findings.
Cloud Cost Management
PERSPECTIVEPERSPECTIVE_BUDGETPERSPECTIVE_REPORTPERSPECTIVE_FOLDERCOST_CATEGORYBUDGET_GROUPAUTOSTOPPING_RULEAUTOSTOPPING_LBAUTOSTOPPING_STARTSTOPCOMMITMENT_ORCHESTRATOR_SETUPCOMMITMENT_ACTIONSCLUSTER_ORCHESTRATOR_SETUPCLUSTER_ORCHESTRATOR_VPA_RULECLUSTER_ACTIONSCCM_ANOMALYCCM_ANOMALY_ALERTCCM_RECOMMENDATIONCCM_RECOMMENDATION_IGNORE_LISTCCM_RECOMMENDATION_SETTINGSCCM_RECOMMENDATION_TICKET_SYSTEMCCM_UNIT_METRICCCM_ANOMALIES_WHITELIST_RULECLOUD_ASSET_GOVERNANCE_RULECLOUD_ASSET_GOVERNANCE_RULE_SETCLOUD_ASSET_GOVERNANCE_RULE_ENFORCEMENTCLOUD_ASSET_GOVERNANCE_RULE_EVALUATIONCLOUD_ASSET_GOVERNANCE_NOTIFICATIONCLOUD_ASSET_GOVERNANCE_RECOMMENDATION
Cost visibility, optimization, anomaly detection, and governance resources for managing cloud spend and efficiency.
Feature Flags
FEATURE_FLAGFEATURE_FLAG_STALE_CONFIGTARGET_GROUP
Feature Flags resources used to control feature rollout and targeting. These audit events apply to Feature Flags resources, not FME entities.
Code Repository
CODE_REPOSITORYCODE_BRANCH_RULECODE_PUSH_RULECODE_TAG_RULECODE_BRANCHCODE_TAGCODE_REPOSITORY_SETTINGSCODE_WEBHOOK
Source code repositories and governance rules for managing code changes and integrations.
Internal Developer Portal
IDP_APP_CONFIGSIDP_CONFIG_ENV_VARIABLESIDP_PROXY_HOSTIDP_SCORECARDSIDP_CHECKSIDP_ALLOW_LISTIDP_OAUTH_CONFIGIDP_CATALOG_CONNECTORIDP_BACKSTAGE_CATALOG_ENTITYIDP_BACKSTAGE_SCAFFOLDER_TASKIDP_LAYOUTIDP_HOMEPAGE_LAYOUTIDP_PERMISSIONSIDP_PLUGINSIDP_GIT_INTEGRATIONSIDP_CATALOG_INTEGRATIONSIDP_CATALOGIDP_CATALOG_DECORATORIDP_CATALOG_TABLEIDP_CATALOG_VERSIONIDP_CATALOG_CUSTOM_PROPERTIESIDP_GROUPSIDP_WORKFLOWIDP_ENVIRONMENTIDP_ENVIRONMENT_BLUEPRINTIDP_AGGREGATION_RULEIDP_KIND
Developer self-service portal resources including service catalog, workflows, scorecards, and integrations.
Supply Chain Security (Software Supply Chain Assurance)
SSCA_ARTIFACTSSCA_COMPLIANCESSCA_COMPONENTS
Artifact and component-level compliance data for securing the software supply chain.
Infrastructure as Code Management
WORKSPACEIAC_MODULE
Workspaces and modules used to manage infrastructure using infrastructure-as-code workflows.
Artifact Registry
ARTIFACT_REGISTRYARTIFACT_REGISTRY_UPSTREAM_PROXY
Artifact registries and upstream proxies for storing and serving build artifacts.
Release Management
RMG_PROCESSRMG_ACTIVITYRMG_PROCESS_INPUTRMG_RELEASE_GROUPRMG_RELEASE
Release orchestration resources used to model and manage release processes and workflows.
Other / System
MODULE_LICENSEEULANETWORK_MAPSERVICE_DISCOVERY_AGENTAPPLICATION_MAPDAEMON_SETRUNNERGITX_WEBHOOKRMGDEFAULT_NOTIFICATION_TEMPLATE_SET
System-level, licensing, and miscellaneous resources used internally or across multiple modules.
Software Engineering Insights (1.0)
SEI_CONFIGURATION_SETTINGSSEI_COLLECTIONSSEI_INSIGHTSSEI_PANORAMA
Metrics, insights, and configurations used to analyze software delivery and engineering performance.
Continuous Error Tracking
CET_AGENT_TOKENCET_CRITICAL_EVENTCET_SAVED_FILTER
Error tracking resources used to capture, filter, and analyze application runtime issues.
Cloud Development Environments (Gitspaces)
CDE_GITSPACECDE_INFRAPROVIDER
Cloud development environments used to provision and manage Git-based workspaces.
Service Reliability Management
MONITORED_SERVICESERVICE_LEVEL_OBJECTIVEDOWNTIMENOTIFICATION_CHANNELNOTIFICATION_RULE
Resources for monitoring service health, defining SLOs, tracking downtime, and sending reliability notifications.
Resource type and supported actions
Each resource in Harness can perform specific actions that reflect how it is created, updated, executed, accessed, or governed across the platform.
All Resources (Generic)
CREATEUPDATEDELETERESTOREMOVE
Core lifecycle actions applicable to most resources across Harness.
Access & Identity Resources (USER, ROLE, SERVICE_ACCOUNT, TOKEN)
INVITEADD_MEMBERSHIPREMOVE_MEMBERSHIPCREATE_TOKENREVOKE_TOKENDELETE_TOKEN
Actions related to managing users, access, and authentication credentials.
Platform Authentication
LOGINLOGIN2FAUNSUCCESSFUL_LOGIN
Records authentication activity for users and service accounts.
Pipeline Resources (PIPELINE, STAGE, INPUT_SET)
STARTENDSTAGE_STARTSTAGE_ENDPAUSERESUMEABORTTIMEOUTRERUN
Actions that track pipeline and stage execution lifecycle.
Governance & Policy Resources
ENABLEDDISABLEDBYPASSFREEZE_BYPASS
Actions that reflect policy state changes or controlled overrides.
Git-Backed Resources (GitOps, Code, IACM)
SYNC_STARTSYNC_SUCCEEDEDSYNC_FAILEDMOVE_TO_GITFORCE_PUSH
Actions related to Git synchronization and source-controlled changes.
SLO & Reliability Resources
ERROR_BUDGET_RESET
Actions associated with SLO and reliability management events.
Feature Flags Resources
ENABLEDDISABLED
Actions indicating Feature Flags state changes. These actions do not apply to FME entities.
Impersonation
START_IMPERSONATIONEND_IMPERSONATION
Tracks when an identity assumes or exits impersonated access.
Tickets & Exceptions
TICKET_CREATEDTICKET_CREATE_FAILEDDISMISS_ANOMALY
Actions representing exceptions, alerts, or external ticketing outcomes.
System & Compliance Events
SIGNED_EULASTABLE_VERSION_CHANGEDEXPIRED
One-time or system-level events recorded for audit and compliance.
Last updated
Was this helpful?