[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-audit-log::en":3,"gloss-cluster-audit-log::en":23,"gloss-next-audit-log::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"audit-log","security","Audit Log (Audit Trail)","An audit log is an append-only record of security-relevant events in your app — who did what, to which resource, and when. Logins, permission changes, data exports, deletions, and admin actions each become an immutable entry with actor, action, target, and timestamp. For SaaS builders, audit logs serve two audiences. Your customers' security teams want them to investigate incidents and prove compliance, so an exportable or streamable audit trail is a common enterprise requirement and a differentiator on higher-tier plans. Your own SOC 2 audit also depends on logging administrative access. Practical note: audit logs are not the same as debug logs — they must be tamper-resistant, retained for a defined period, and never contain secrets or full PII payloads. Capture them at a chokepoint (a service layer or middleware) so events aren't silently missed, and record the actor's identity, not just an internal ID. Design the schema early; backfilling history you never captured is impossible.","An audit log is an append-only record of who did what to which resource and when — logins, permission changes, exports, deletions, every admin action.",null,[11,14,17,20],{"slug":12,"name":13},"rbac","Role-Based Access Control (RBAC)",{"slug":15,"name":16},"scim","SCIM (System for Cross-domain Identity Management)",{"slug":18,"name":19},"soc-2","SOC 2",{"slug":21,"name":22},"zero-trust","Zero-Trust Architecture",[24,28,32,35,38,42,45,48,51,54,57,60],{"slug":25,"category":5,"name":26,"updated_at":27},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":29,"category":5,"name":30,"updated_at":31},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":33,"category":5,"name":34,"updated_at":31},"bridge-letter","Bridge Letter",{"slug":36,"category":5,"name":37,"updated_at":31},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":39,"category":5,"name":40,"updated_at":41},"byok","Bring Your Own Key (BYOK)","2026-08-24T02:46:37+00:00",{"slug":43,"category":5,"name":44,"updated_at":31},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":46,"category":5,"name":47,"updated_at":27},"data-classification","Data Classification",{"slug":49,"category":5,"name":50,"updated_at":31},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":52,"category":5,"name":53,"updated_at":31},"data-minimization","Data Minimization",{"slug":55,"category":5,"name":56,"updated_at":31},"data-poisoning","Data Poisoning",{"slug":58,"category":5,"name":59,"updated_at":31},"data-processing-agreement","Data Processing Agreement (DPA)",{"slug":61,"category":5,"name":62,"updated_at":41},"data-retention","Data Retention Policy"]