All resources
Operate4 min read

Who did what: the audit log and execution history

Two records answer two different questions: what happened inside a process, and who changed something in the platform.

In short

  • 01

    Execution history: every step of one process instance.

  • 02

    Audit log: every change made through the API, by whom.

  • 03

    The audit log never stores request bodies, tokens or variable values.

Execution historyAudit log
AnswersWhat happened in this instance?Who did what, and when?
ScopeOne process instanceThe whole tenant
RecordsSteps, jobs, tasks, timers, messages, variable snapshotsEvery create, update and delete call
Who can read itAny signed-in user in the tenantAdmins only

Execution history

Every instance keeps a timeline, oldest event first: the instance started, a step was visited, a job was created and completed, a task was claimed, a timer fired. Each event carries the variables as they were at that moment.

Manual interventions appear in the same timeline. If someone edits variables, moves a token or cancels the instance, the event names the person who did it.

Audit log

Every state-changing request is recorded automatically — new features are covered without extra work. Reads are not recorded.

FieldExample
Whoalice
Actiondeployments.delete
ResourceThe deployment's id
OutcomeSuccess, Denied or Failed
Where fromThe caller's IP address
When2026-10-03 10:15

Filtering

In the app's Audit Log page, or through the API, filter by person, action, resource, outcome and date range. Filtering by action matches the start of the name, so "process-instances" finds every action on instances.

curl -G http://localhost:3000/api/v1/audit-events \
  -H "Authorization: Bearer $TOKEN" \
  --data-urlencode "action=process-instances" \
  --data-urlencode "outcome=DENIED"

What is left out

  • Request bodies, query strings, tokens and variable values are never stored.
  • High-volume calls that change nothing meaningful — worker polling, heartbeats, test evaluations and draft autosave — are not recorded.
  • A request with a missing or invalid token is rejected before it reaches the audit log. A request refused for lacking a role is recorded as Denied.

See it on your own process

Book a walkthrough with the Orkovia team.

Request a Demo