Audit export format
Columns of the CSV export and fields of the JSON export of the audit log, with every event type and result.
You can export the audit log of your workspace as CSV or JSON on the audit page: Audit, then Export CSV or Export JSON. Only owners and admins can open the audit page. An export contains exactly the entries the page shows with your filters (team, actor, event, run, time range), one entry per row or object, newest first, at most 5,000 entries. See Audit for the page.
CSV
The header line is always:
timestamp,actor,team,run,event,result
| Column | Content | Example |
|---|---|---|
timestamp |
Time of the event, ISO 8601 with microseconds and the UTC offset | 2026-10-01T09:00:00.000000+00:00 |
actor |
Display name of the person, or kanman, or system |
Lena Weber |
team |
Team slug, empty for workspace-level events | sandbox-team |
run |
Run key, empty when the event has no run | run-2m9q |
event |
Event type, see below | policy_decision |
result |
Result, see below | denied |
Example:
timestamp,actor,team,run,event,result
2026-10-01T09:12:31.000000+00:00,Lena Weber,sandbox-team,run-2m9q,decision_resolved,rejected
2026-10-01T09:00:01.000000+00:00,kanman,sandbox-team,run-2m9q,decision_created,info
2026-10-01T09:00:00.000000+00:00,kanman,sandbox-team,run-2m9q,policy_decision,denied
2026-10-01T08:58:30.000000+00:00,kanman,sandbox-team,run-2m9q,run_state_changed,info
2026-10-01T08:41:07.000000+00:00,Lena Weber,sandbox-team,,story_written,info
Formatting rules:
- UTF-8, one entry per line, lines end with a line feed.
- A field that contains a comma, a quote or a line break is quoted; quotes inside a field are doubled.
- Empty fields stay empty (no
null). - A value that starts with
=,+,-or@is prefixed with an apostrophe ('), so spreadsheet programs never run it as a formula. - The CSV holds the six columns only. Use the JSON export when you need details such as the denied path or old and new policy values.
JSON
The JSON export is an array of objects, one per entry, in the same order as the page:
[
{
"timestamp": "2026-10-01T09:00:00.000000+00:00",
"actor": "kanman",
"actorType": "kanman",
"team": "sandbox-team",
"run": "run-2m9q",
"event": "policy_decision",
"result": "denied",
"entityType": "run",
"entityName": "SBX-14 Add health check alarm",
"details": {
"check": { "kind": "path", "subject": "infra/alarms.tf" },
"verdict": { "allowed": false, "authority": "ESCALATE", "reasonKey": "policy.path.denied" },
"policyVersion": 3,
"presetId": "balanced"
}
}
]
| Field | Type | Description |
|---|---|---|
timestamp |
string | ISO 8601 with microseconds and the UTC offset. |
actor |
string | Display name of the person; kanman or system for those actors. |
actorType |
string | human, kanman or system. |
team |
string or null | Team slug. |
run |
string or null | Run key. |
event |
string | Event type. |
result |
string or null | Result. |
entityType |
string | task (a story), run, decision, policy, convention or team. |
entityName |
string or null | Readable name at the time of the event. |
details |
object | Event-specific details. Never contains secret values or model prompts. |
Event types
| Event | Recorded when | Typical results |
|---|---|---|
policy_decision |
kanman checks something against the team policy (path, repo, diff size, budget, hours, concurrency, plan approval, merge) | allowed, denied |
policy_changed |
An admin changes the team policy (old and new values in details) |
info |
decision_created |
A decision lands in the inbox | info |
decision_resolved |
A person answers a decision (option and channel in details) |
approved, rejected, info |
story_drafted |
Intake drafts a story from a requirement | info |
story_written |
An approved story is written to the tracker | info |
run_state_changed |
A run changes status or stage | info, failed |
gate_passed |
A gate of the outcome gate passes (gate id in details) |
passed |
gate_failed |
A gate fails, for example diff_guard |
failed |
tracker_write |
kanman writes to the tracker (comment, transition, link) | info |
budget_reserved |
Listed in the event filter, not recorded at the moment | none |
budget_stop |
A run is stopped because its budget is used up | denied |
convention_changed |
A convention is pinned, edited or retired | info |
merge |
A pull request is merged | approved, info |
revert_opened |
kanman opens a revert pull request | info |
team_paused |
A team is paused | info |
team_resumed |
A team is resumed | info |
team_deleted |
The workspace owner deletes a team (cancelled runs and decisions in details) |
info |
workspace_deleted |
The owner deletes the workspace | info |
audit_retention_applied |
Entries older than the retention period were removed (count and cut-off in details) |
info |
Results
| Result | Meaning |
|---|---|
allowed |
A policy or budget check passed. |
denied |
A policy or budget check blocked the action. |
passed |
A gate passed. |
failed |
A gate or run failed. |
approved |
A person approved (a plan, an exception, a merge). |
rejected |
A person rejected. |
info |
Recorded for the trail, no verdict. |
Integrity and retention
- The audit log is append-only. Entries cannot be edited, not even by admins.
- Entries older than your retention period are deleted automatically. Admins set the period under Settings, Audit retention. See Retention and deletion.
- kanman keeps a record of every export: who exported, when, the format and the date range.
Last updated: January 1, 0001
Open kanman