Audit log
Changes to people, apps, secrets and settings are recorded, with export.
Plans: Every plan, including the free app
What you get
- Changes to people, roles, groups and app access
- Deploys, database snapshots and restores
- Secret changes
- Data changes made by coding agents
- Agent actions shown with the person they act for
- Filters by date, person and action
- Export as CSV or JSON Lines
How it works
Whisk records every change made through the dashboard, the CLI, the API or an app's own token: who made it, when, from which address, and what it was before and after. Entries can only be added, never edited. They are kept for as long as the business is active.
When a coding agent acts, the entry names the agent and the person who approved it, such as "Claude Code, acting for Dana". Database queries an agent runs are recorded too. Each secret also keeps its own list of when its value was delivered to a running app.
Owners, admins, developers and billing contacts read the log in the dashboard, filtered by date, person and action. It downloads as CSV or JSON Lines for an auditor or another system. Who may open each app is set under team sign-in.
Example
An HVAC contractor's insurer asks who changed access to the job pricing app last quarter. The office manager filters the log to access changes for those months and sends the export.
For your coding agent
whisk secrets reads <SECRET_NAME> --since 30d
This lists when and by which container a secret's value was delivered. Commands an agent runs, such as whisk deploy and whisk db query, are recorded under the agent's name and the person it acts for; the commands are in the CLI reference.