What is a muniment audit record?

In the local app, the graph’s append-only event log will record every write on the machine. No account will exist in the local app. In the paid console, audit records will cover shared work, routing enforcement, and runs that happen without you. The owner will read them in the Records area of the console.

These features will be available at launch. muniment is not generally available. The rest of this guide describes the paid console.

What a record holds

A route receipt will name the matched route, model, cost, time, capability, and capability version. A privileged-decision record will hold the actor, matched rule, cost, and time.

Actions that create records

The paid console will record an audit event when it checks entitlements and action policy. Audit records will cover routes, grant changes, policy publishes, and denied requests. The console rules will limit each agent to the authority of the human it acts for.

For a paid console run, a remote approval will add the answer to the run receipt. The answers will be Allow once, Allow for this thread, or Deny.

Where owners read records

At launch, the owner will read audit records and usage in the Records area of the paid console. Public visitors cannot access the paid console today.

Read how the bring your own key guide connects provider credentials with audit records.

Search docs

Join the waitlist

Get desktop release updates.

We will email you about desktop releases and new features. muniment is a desktop workspace for your models, tools, and files.