V8 Central — Product & Technical Spec
  1. Docs
  2. Modules
  3. Audit log

#Audit log

The audit log answers: who did what, to which resource, when, from where, and did it work.

#What exists

SourceShape
V7 V7 onlyactivities: organization_id, user_id, server_id, ip, on (area, e.g. Organization, Server, Application, Subscription, Firewall), action (Create, Update, Delete, Invite, Verify…), content (free text sentence), timestamps. Endpoints: GET /activities (mine), GET /organizations/{org}/activities, GET /organizations/{org}/servers/{server}/activities
OSS OSS APIPer-server activity log with typed verbs and a scope (account/server). Every action Central takes is logged as the "central" machine account, not the person
V8 docPhase 3.12 "Activity log: account activity only" (login, password, 2FA, settings). Server/app activity comes from OSS. Organization activity is now specified: Phase 4 (4.8) covers organization, member, role, share and transfer actions, Phase 5 (5.16) adds every integration action, and Phase 7 (7.16) adds every plan change, renew, cancel and resume — connect, edit, add to other servers, update everywhere, remove, disconnect — with who, which account, which servers and when, and never a token or key (2026-10-03) V8 requirement

#Proposed V8 entry

FieldExampleWhy
id, occurred_atOrder, display
organization_idScope
actoruser id + name/email snapshotStays readable after the user is deleted (the OSS bug "deleted users turn into System" must not be repeated)
actor_typeuser · system · api_tokenShow "System" only for real automatic jobs
actionmember.invited, server.connected, plan.upgraded, subscription.changed, blueprint.deployed, role.updatedTranslatable key, filterable
resource_type / resource_id / resource_labelserver / 42 / "web-01"Link to the resource, readable after deletion
statussuccess · failedFailed attempts matter (e.g. failed server connect)
detailsJSON: before/after, error code, OSS referenceExpandable row
ip, user_agentSecurity

#Examples

ActionWhoResourceDetails
member.invitedOwnerinvitation (email)roles
member.role_changedAdminmemberbefore → after
server.connectedAdminserverOSS version
server.disconnectedOwnerserver—
server.actionDeveloperserver/appOSS path + status (e.g. "restarted nginx")
plan.upgraded / subscription.changedOwnersubscriptionplan/cycle before → after, amount
payment.succeeded / payment.failedOwnertransactiongateway, amount
blueprint.deployedAdminblueprint → siterun id, completed
role.created / role.updated / role.deletedAdminrolepermission diff

#Audit Log page (/[locale]/audit-log)

  • Table: time (relative + exact on hover), actor, action (translated), resource (link if it still exists), status badge, IP. Expandable details.
  • Filters: actor, action group (members, servers, billing, roles, account…), resource type, status, date range. Search: resource label / actor email.
  • Pagination (server-side). Export CSV for owners Assumption.
  • Dashboard "Recent activity" shows the last N entries and links here with the same filters.
  • Server Details → Activity tab can show the OSS activity log for that server, labelled "Server log (actions by Central appear as 'central')".

Permission: view audit = Owner, Admin. See Roles & permissions.

ServerAvatar V8 Central · prepared by central-app-2 (Pair 2 frontend) for Bhavik Jethwa · nothing in this spec is implemented yet · Built 2026-10-03 12:35 UTC