Audit Log
Organization-level audit events that record who did what in your Factory organization.
The Factory audit log records organization-level events so you can track who did what in your organization. Each event captures who acted, where the action originated, what was affected, and structured details about the change.
Enterprise Feature -- The audit log is available to Enterprise organization owners only. Owners can view the audit log in the Factory web app under Team Settings, or via the public API.
Overview
Every audit event includes:
- Actor -- the user or service principal who initiated the action (or
nullfor system-initiated events). - Source -- the surface that originated the event (e.g. web settings pages, public API, identity provider webhooks).
- Target -- identifiers for the affected entity (e.g. user, service account, integration).
- Payload -- structured, event-specific details, such as IDs, settings values, and enum values, never secrets.
- Timestamp -- ISO 8601 timestamp of the event.
Event categories
Audit events cover the following categories of organization activity:
- Usage limits -- per-user token usage limit changes.
- Usage alerts -- organization monthly alert threshold and alert email setting changes.
- Membership -- role changes, invitations, and member removals.
- API keys -- creation and deletion of user and service-account API keys.
- Service accounts -- creation, modification, deletion, and credential/grant changes.
- Integrations -- connection, disconnection, configuration, and availability toggles.
- Organization lifecycle -- creation and deactivation of organizations.
- Managed settings -- updates to org-managed settings (with revision tracking for before/after diffing).
- Analytics settings -- updates to org-wide analytics preferences.
Organization usage alert settings
Changes to the organization usage alert settings record an organization_monthly_usage_settings_change event with source web_settings_usage. The event identifies the Owner or Manager who made the change and includes:
| Payload field | Meaning |
|---|---|
previousMonthlyLimitFsc | Previous monthly alert threshold in FSC, or null if none was set. |
monthlyLimitFsc | New monthly alert threshold in FSC, or null if removed. |
previousAlertEmailsEnabled | Whether organization alert emails were enabled before the change. |
alertEmailsEnabled | Whether organization alert emails are enabled after the change. |
Despite the Limit field names, these values describe an informational alert threshold, not an enforced usage cap. The event records settings changes, not threshold crossings or email deliveries. Saving unchanged settings does not create an event.