Audit Log

Track changes to Remote Workspaces and workspace templates — who made each change, when it happened, and what changed.

The Audit Log records changes to Remote Workspaces and workspace templates in your organization. Each recorded event shows who made the change, when it happened, and what changed — with old and new values side by side.

Audit events are recorded automatically. There is nothing to enable or configure.

Use the Audit Log to answer questions such as who deleted a workspace, when a template's definition changed, or which quota limit refused a workspace creation.

What is recorded

Workspace events

EventRecorded whenWhat it captures
Workspace createdA workspace is createdWorkspace ID, name, cluster, template, and client type
Workspace updatedA workspace's details changeThe workspace's details before and after the change — mainly its description
Workspace deletedA workspace is deletedWorkspace ID, name, and cluster
Workspace suspendedA workspace is suspendedThe workspace's status before suspension
Workspace resumedA suspended workspace is resumedThe status change back to active
Workspace visibility changedWho can see a workspace changesThe visibility configuration before and after — for example, switching between a private workspace and one shared with the whole organization

Workspace template events

Workspace templates define reusable configurations for creating workspaces.

EventRecorded whenWhat it captures
Template createdA template is createdTemplate name, description, and full definition
Template updatedA template's definition or description changesThe new definition and the description before and after
Template deletedA template is deletedTemplate name, and the user who deleted it
📘

When a workspace template is deleted, the audit event records the user who deleted it, not the user who originally created the template.

Quota-denied events

Attempts to create or resume a workspace that are refused because an organization or user quota limit was reached are also recorded, with warning severity. The event shows which action was refused, whether the organization or user limit was exceeded, and why.

All other events are recorded with informational severity.

Event details

Every audit event includes:

  • Actor — the user who made the change.
  • Timestamp — when the change happened.
  • Change details — old and new values for updated fields, such as description, status, and visibility.
  • Cluster — workspace events carry the Kimchi cluster the workspace belongs to.

Events are recorded only after the change is committed, so the Audit Log reflects changes that actually happened — not attempts that failed.

View the Audit Log

Open the Audit Log page in the Kimchi console to browse the recorded events for your organization.

What is not recorded

  • Activity inside a workspace — sessions, commands, and file changes — is not audited. Only workspace and workspace template changes are recorded.
  • Changes to member roles are not recorded in the audit log. See User Roles.

See also

  • Remote Workspaces — Workspaces and sessions, /teleport, and Remote Execution.
  • User Roles — Manage who has access to your organization and what each person can do.

Did this page help you?