Audit logs
Root users can view application event audit logs from the Admin panel Audit logs tab.
Application event audit logs are retained for 365 days by default. In Platform Enterprise, this retention period can be customized. You can also disable automatic audit log deletion with TOWER_CRON_AUDIT_LOG_CLEAN_UP_ENABLED.
Audit log versions
Seqera Platform Enterprise 26.1 introduced the audit log v2 schema as a breaking change for direct database consumers and custom ETL jobs. From 26.2, v2 is the only schema that receives new events.
- The
TOWER_AUDIT_LOG_V2_WRITE_MODEsetting is removed. Setting the variable has no effect. Remove it from your configuration. - Platform writes no new rows to the legacy v1 schema (
tw_audit_logtable). Existing rows remain until the audit log retention period deletes them. As long as the table has records, they stay visible in the legacy table view of the Admin panel Audit logs tab.
Upgrade path for existing integrations
If you have existing scripts, exports, or ETL processes that read from the legacy audit log schema, switch them to the v2 schema before upgrading to 26.2:
- On 26.1, validate your integrations against the v2 schema while your existing v1 readers continue to work from the legacy v1 schema. Audit log v2 entries are available through the public API at
/admin/audit-logs-v2, with a CSV export at/admin/audit-logs-v2/export-csv. - Point every reader at the v2 schema.
- Upgrade to 26.2.
Audit log event format
The Admin panel shows the following event details:
- Timestamp: Event timestamp in ISO 8601 format.
- Event: The audit event name, such as
user_sign_inorcredentials_created. - Actor: Whether a user, a service account, or the system triggered the event, including point-in-time identity details for user- and service-account-initiated events. Where an agent acted under a service account, the actor also carries an Agent ID, which is the agent's raw identifier rather than a name.
- Client: Client IP address, user agent, and access token ID when available. Client details are empty for system-initiated events.
- Target: The resource type, ID, and resource name associated with the event.
- Organization: The organization ID and name for organization-scoped or workspace-scoped resources.
- Workspace: The workspace ID and name for workspace-scoped resources.
- Correlation ID: An identifier that links all audit events emitted as part of the same cascade action.
For organization-scoped, personal workspace-scoped, or system-wide targets, the organization and workspace columns display N/A labels to indicate when a field does not apply to that resource scope.
Service account authentication is not audited. Service accounts cannot sign in, and bearer-token validation does not raise a user_sign_in event. No service account appears in sign-in events or sign-in metrics. The audit log records what a service account did, not that it authenticated.
If you parse the Actor field, update your integration to handle the service_account actor type before upgrading.
CSV exports use the same v2 schema and date filters as the Admin panel view. You can control the maximum export size with TOWER_AUDIT_LOG_V2_CSV_EXPORT_MAX_LOGS.
Audit log v2 events
Audit log v2 emits the following event names.
Event | Target | Description |
|---|---|---|
| Workflow run | A workflow run was launched from Platform. |
| Workflow run | A workflow run was created after Nextflow established connection. |
| Workflow run | A workflow run was updated. |
| Workflow run | A workflow run completed execution. |
| Workflow run | A workflow run was deleted. |
| Workflow run | A workflow run was permanently deleted. |
| Access token | A personal access token was created. |
| Access token | A personal access token was deleted. |
| SSH key | An SSH public key was added to a user account. |
| SSH key | An SSH public key was removed from a user account. |
| User | A new user account was created. |
| User | A user account was updated. |
| User | A user account was deleted. |
| User | A user signed in to the platform. |
| Compute environment | A compute environment was created. |
| Compute environment | A compute environment was updated. |
| Compute environment | A compute environment was deleted. |
| Credentials | Credentials were created. |
| Credentials | Credentials were updated. |
| Credentials | Credentials were deleted. |
| Credentials | Credentials were permanently deleted. |
| Action | A pipeline action was created. |
| Action | A pipeline action was updated. |
| Action | A pipeline action was deleted. |
| Organization | An organization was created. |
| Organization | An organization was updated. |
| Organization | An organization was deleted. |
| Team | A team was created. |
| Team | A team was updated. |
| Team | A team was deleted. |
| Workspace | A workspace was created. |
| Workspace | A workspace was updated. |
| Workspace | A workspace was deleted. |
| Pipeline | A pipeline was added to a workspace launchpad. |
| Pipeline | A pipeline was updated. |
| Pipeline | A pipeline was deleted from a workspace launchpad. |
| Participant | A user or team was added as a participant to a workspace. |
| Participant | A user or team was removed as a participant from a workspace. |
| Participant | A workspace participant role was changed in a workspace. |
| Member | A user was added as a member to an organization. |
| Member | A user was removed as a member from the organization. |
| Member | A member role was changed in an organization. |
| Team member | A member was added to a team. |
| Team member | A member was deleted from a team. |
| Pipeline secret | A pipeline secret was created. |
| Pipeline secret | A pipeline secret was updated. |
| Pipeline secret | A pipeline secret was deleted. |
| Dataset | A dataset was created. |
| Dataset | A dataset was updated. |
| Dataset | A dataset was deleted. |
| Dataset | Dataset content was uploaded. |
| Dataset | Dataset content was downloaded. |
| Data-link | A data-link was created. |
| Data-link | A data-link was updated. |
| Data-link | A data-link was deleted. |
| Data-link (metadata) | A data-link was hidden from the workspace. |
| Data-link (metadata) | A hidden data-link was made visible in the workspace. |
| Data-link (file) | A file was previewed through a data-link. |
| Data-link (file) | A file was uploaded through a data-link. |
| Data-link (file) | A file was downloaded through a data-link. |
| Data-link (file) | A file was deleted through a data-link. |
| Studio | A studio session was created. |
| Studio | A studio session was deleted. |
| Studio | A studio session was started. |
| Studio | A studio session was stopped. |
| Studio | A studio session was updated. |
| Studio (connection) | A user connected to a studio session. |
| Studio (connection) | A user disconnected from a studio session. |
| Studio | A studio session container build was started. |
| Studio | A studio session container build failed. |
| Studio | A studio session container build succeeded. |
| Studio | A studio session lifespan was extended. |
| Studio (SSH) | SSH authentication to a studio session succeeded. |
| Studio (SSH) | SSH authentication to a studio session failed. |
| Label | A label was created. |
| Label | A label was updated. |
| Label | A label was deleted. |
| Label | A resource label was created. |
| Label | A resource label was updated. |
| Label | A resource label was deleted. |
| Label assignment | A label was assigned to a resource. |
| Label assignment | A label was removed from a resource. |
| Managed identity | A managed identity was created. |
| Managed identity | A managed identity was updated. |
| Managed identity | A managed identity was deleted. |
| Managed credentials | Managed credentials were created. |
| Managed credentials | Managed credentials were updated. |
| Managed credentials | Managed credentials were deleted. |
| Credit info | A credit grant was modified. |
| User role | A role was assigned to a user. Note: this can happen via changes to the user's team (namely, team role changes). |
| User role | A user's role was updated. Note: this can happen via changes to the user's team (namely, team role changes). |
| User role | A user's role was removed. |
| Role | A custom role was created. |
| Role | A custom role was updated. |
| Role | A custom role was deleted. |
| IdP group | An IdP group was created. |
| IdP group | An IdP group was updated. |
| IdP group | An IdP group was deleted. |
| Service account | A service account was created. |
| Service account | A service account was updated. |
| Service account | A service account was deleted. |
Deprecated audit events
The following legacy event names are deprecated. Use the replacement event when one is available.
Event | Replacement |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
| |
|
|
|
|
|
|
|
|
|
|
|
|
Pre and post state change capture
When enabled, audit log v2 captures full resource state snapshots or images immediately before and after each change event in JSON format. This provides a complete record of what changed and satisfies regulatory requirements (such as GxP/21 CFR Part 11). Fields that are large or that may contain sensitive values are hashed.
State snapshots increase database storage requirements. For a deployment with 2 million audit log records, the snapshots can consume between 3 GB and 40 GB depending on the events and the size and complexity of the tracked resources. Plan your database capacity and retention policy accordingly before enabling this feature.
This feature is enabled once the GxP add-on is attached to your Seqera license. Contact us to obtain the GxP add-on.