Audit export format

Columns of the CSV export and fields of the JSON export of the audit log, with every event type and result.

You can export the audit log of your workspace as CSV or JSON on the audit page: Audit, then Export CSV or Export JSON. Only owners and admins can open the audit page. An export contains exactly the entries the page shows with your filters (team, actor, event, run, time range), one entry per row or object, newest first, at most 5,000 entries. See Audit for the page.

CSV

The header line is always:

timestamp,actor,team,run,event,result
Column Content Example
timestamp Time of the event, ISO 8601 with microseconds and the UTC offset 2026-10-01T09:00:00.000000+00:00
actor Display name of the person, or kanman, or system Lena Weber
team Team slug, empty for workspace-level events sandbox-team
run Run key, empty when the event has no run run-2m9q
event Event type, see below policy_decision
result Result, see below denied

Example:

timestamp,actor,team,run,event,result
2026-10-01T09:12:31.000000+00:00,Lena Weber,sandbox-team,run-2m9q,decision_resolved,rejected
2026-10-01T09:00:01.000000+00:00,kanman,sandbox-team,run-2m9q,decision_created,info
2026-10-01T09:00:00.000000+00:00,kanman,sandbox-team,run-2m9q,policy_decision,denied
2026-10-01T08:58:30.000000+00:00,kanman,sandbox-team,run-2m9q,run_state_changed,info
2026-10-01T08:41:07.000000+00:00,Lena Weber,sandbox-team,,story_written,info

Formatting rules:

  • UTF-8, one entry per line, lines end with a line feed.
  • A field that contains a comma, a quote or a line break is quoted; quotes inside a field are doubled.
  • Empty fields stay empty (no null).
  • A value that starts with =, +, - or @ is prefixed with an apostrophe ('), so spreadsheet programs never run it as a formula.
  • The CSV holds the six columns only. Use the JSON export when you need details such as the denied path or old and new policy values.

JSON

The JSON export is an array of objects, one per entry, in the same order as the page:

[
  {
    "timestamp": "2026-10-01T09:00:00.000000+00:00",
    "actor": "kanman",
    "actorType": "kanman",
    "team": "sandbox-team",
    "run": "run-2m9q",
    "event": "policy_decision",
    "result": "denied",
    "entityType": "run",
    "entityName": "SBX-14 Add health check alarm",
    "details": {
      "check": { "kind": "path", "subject": "infra/alarms.tf" },
      "verdict": { "allowed": false, "authority": "ESCALATE", "reasonKey": "policy.path.denied" },
      "policyVersion": 3,
      "presetId": "balanced"
    }
  }
]
Field Type Description
timestamp string ISO 8601 with microseconds and the UTC offset.
actor string Display name of the person; kanman or system for those actors.
actorType string human, kanman or system.
team string or null Team slug.
run string or null Run key.
event string Event type.
result string or null Result.
entityType string task (a story), run, decision, policy, convention or team.
entityName string or null Readable name at the time of the event.
details object Event-specific details. Never contains secret values or model prompts.

Event types

Event Recorded when Typical results
policy_decision kanman checks something against the team policy (path, repo, diff size, budget, hours, concurrency, plan approval, merge) allowed, denied
policy_changed An admin changes the team policy (old and new values in details) info
decision_created A decision lands in the inbox info
decision_resolved A person answers a decision (option and channel in details) approved, rejected, info
story_drafted Intake drafts a story from a requirement info
story_written An approved story is written to the tracker info
run_state_changed A run changes status or stage info, failed
gate_passed A gate of the outcome gate passes (gate id in details) passed
gate_failed A gate fails, for example diff_guard failed
tracker_write kanman writes to the tracker (comment, transition, link) info
budget_reserved Listed in the event filter, not recorded at the moment none
budget_stop A run is stopped because its budget is used up denied
convention_changed A convention is pinned, edited or retired info
merge A pull request is merged approved, info
revert_opened kanman opens a revert pull request info
team_paused A team is paused info
team_resumed A team is resumed info
team_deleted The workspace owner deletes a team (cancelled runs and decisions in details) info
workspace_deleted The owner deletes the workspace info
audit_retention_applied Entries older than the retention period were removed (count and cut-off in details) info

Results

Result Meaning
allowed A policy or budget check passed.
denied A policy or budget check blocked the action.
passed A gate passed.
failed A gate or run failed.
approved A person approved (a plan, an exception, a merge).
rejected A person rejected.
info Recorded for the trail, no verdict.

Integrity and retention

  • The audit log is append-only. Entries cannot be edited, not even by admins.
  • Entries older than your retention period are deleted automatically. Admins set the period under Settings, Audit retention. See Retention and deletion.
  • kanman keeps a record of every export: who exported, when, the format and the date range.

Last updated: January 1, 0001

Open kanman