Audit Log
Track changes to Remote Workspaces and workspace templates — who made each change, when it happened, and what changed.
The Audit Log records changes to Remote Workspaces and workspace templates in your organization. Each recorded event shows who made the change, when it happened, and what changed — with old and new values side by side.
Audit events are recorded automatically. There is nothing to enable or configure.
Use the Audit Log to answer questions such as who deleted a workspace, when a template's definition changed, or which quota limit refused a workspace creation.
What is recorded
Workspace events
| Event | Recorded when | What it captures |
|---|---|---|
| Workspace created | A workspace is created | Workspace ID, name, cluster, template, and client type |
| Workspace updated | A workspace's details change | The workspace's details before and after the change — mainly its description |
| Workspace deleted | A workspace is deleted | Workspace ID, name, and cluster |
| Workspace suspended | A workspace is suspended | The workspace's status before suspension |
| Workspace resumed | A suspended workspace is resumed | The status change back to active |
| Workspace visibility changed | Who can see a workspace changes | The visibility configuration before and after — for example, switching between a private workspace and one shared with the whole organization |
Workspace template events
Workspace templates define reusable configurations for creating workspaces.
| Event | Recorded when | What it captures |
|---|---|---|
| Template created | A template is created | Template name, description, and full definition |
| Template updated | A template's definition or description changes | The new definition and the description before and after |
| Template deleted | A template is deleted | Template name, and the user who deleted it |
When a workspace template is deleted, the audit event records the user who deleted it, not the user who originally created the template.
Quota-denied events
Attempts to create or resume a workspace that are refused because an organization or user quota limit was reached are also recorded, with warning severity. The event shows which action was refused, whether the organization or user limit was exceeded, and why.
All other events are recorded with informational severity.
Event details
Every audit event includes:
- Actor — the user who made the change.
- Timestamp — when the change happened.
- Change details — old and new values for updated fields, such as description, status, and visibility.
- Cluster — workspace events carry the Kimchi cluster the workspace belongs to.
Events are recorded only after the change is committed, so the Audit Log reflects changes that actually happened — not attempts that failed.
View the Audit Log
Open the Audit Log page in the Kimchi console to browse the recorded events for your organization.
What is not recorded
- Activity inside a workspace — sessions, commands, and file changes — is not audited. Only workspace and workspace template changes are recorded.
- Changes to member roles are not recorded in the audit log. See User Roles.
See also
- Remote Workspaces — Workspaces and sessions,
/teleport, and Remote Execution. - User Roles — Manage who has access to your organization and what each person can do.
Updated 1 day ago