Audit Logs
A record of everything that happens in your organization, from sign-ins and configuration changes to every MCP call
Introduction
Gatana keeps an audit log of everything that happens in your organization:
- every MCP request, including each tool call
- every sign-in
- every change to a resource: servers, credentials, profiles, teams, skills, artifacts, secret stores, and organization settings
Each record names the identity behind the event: the user, the profiles that were active, and the credential the call came through, whether an OAuth client or a personal access token. This lets you answer "what did this client do?" even when several clients act as the same user.
Open Audit Logs in the left sidebar to read the log. Organization owners see all records; everyone else sees their own activity.
Logging Detail
How much an MCP call records is set by the MCP audit log level in your organization settings:
| Level | What a call records |
|---|---|
off | MCP calls are not recorded |
terse (default) | The server, the tool, the duration, and who called it |
detailed | Adds the call arguments |
detailed-with-error | Adds the response of failed calls |
verbose | Adds the response of every call |
Sign-ins and resource changes are always recorded, whatever the level.
Filtering
The list opens on the last 7 days, with a date control for other ranges. Add filter builds conditions from a field, a comparison (is, is not, contains; for dates is after and is before), and a value. You can filter by event name, resource type, user, OAuth client, access token, server, tool, profile, team, credential, and secret store. Known values are offered as pick lists, so you point at a client by name instead of typing its id. A record must match all conditions, and the filters are kept in the page URL, so a view can be bookmarked or shared.
The same conditions work on the audit log endpoints of the public API, as a repeated query parameter of the form filter=field:operator:value:
GET /api/v1/audit-logs?filter=clientId:eq:CLIENT_ID&filter=toolName:contains:searchThe fields are eventName, entityType, entityId, userId, date, clientId, patId, serverSlug, toolName, profileId, teamId, credentialId, and secretStoreId.
Streaming to Your SIEM
To push audit events to a security platform you control, with your own retention, dashboards, and detection rules, see SIEM Streaming.