Unqork logs administrative and configuration activity across the platform. Audit logs capture who performed an action, what changed, and whether it succeeded. Each entry provides a traceable record for compliance, troubleshooting, and security review.
Audit logs are not available through the UnqorkAI platform. Access is through the API Reference using the GET /logs/audit-logs endpoint. Designer Administrator access is required.
Event Structure
Each audit log entry includes the following fields:
Field | Description |
|---|---|
| The ID of the Creator who performed the action. |
| The specific action performed. Use this field to filter events in SIEM queries. |
| The origin of the action. |
| Whether the action succeeded ( |
For modification events, the log also captures the prior state of the resource for before-and-after comparison.
Logged Events
The following tables list each tracked eventAction value by category. For the full attribute schemas returned with each event, see the payload reference articles linked in See Also.
Applications
| Description |
|---|---|
| An application was created. |
| An application's settings were changed. |
| An application was deleted. |
| An application was promoted to another environment. |
| An application was exported. |
| An application was moved to a different workspace. |
| An application was previewed. |
| A library module was added to an application. |
| A Creator searched for an application's library module. |
| A library module's sharing settings were changed. |
Client Tracker Administration
| Description |
|---|---|
| A Datadog RUM tracker was created. |
| A Datadog RUM tracker was changed. |
| A Datadog RUM tracker was deleted. |
| A LogRocket tracker was created. |
| A LogRocket tracker was changed. |
| A LogRocket tracker was deleted. |
| A New Relic tracker was created. |
| A New Relic tracker was changed. |
| A New Relic tracker was deleted. |
Creator Roles
| Description |
|---|---|
| A Creator role was created. |
| A Creator role's settings were changed. |
| A Creator role was deleted. |
| A Creator's role assignments were changed. |
Creator Users
| Description |
|---|---|
| A Creator account was created. |
| A Creator account's profile was changed. |
| A Creator account was deleted. |
| A Creator's password was changed. |
| A Creator's temporary password was resent. |
| A Creator logged in. |
| A Creator logged out. |
| A Creator account was locked out. |
Email Templates
| Description |
|---|---|
| An email template's content or subject line was changed. |
Environment Administration
| Description |
|---|---|
| API rate limiting settings were changed. |
| Attachment upload limit settings were changed. |
| CORS settings were changed. |
| Component security (safe HTML filters) settings were changed. |
| Express Content Security Policy settings were changed. |
| Express session administration settings were changed. |
| Express user account password settings were changed. |
| Express user account lockout settings were changed. |
| Execution file upload limit settings were changed. |
| Hide Preview Bar by Default settings were changed. |
| Component execution loop limit settings were changed. |
| Workflow node execution loop limit settings were changed. |
| Offline mode settings were changed. |
| OAuth password grant settings were changed. |
| PagerDuty key settings were changed. |
| Password requirement settings were changed. |
| Server-side execution log settings were changed. |
| The environment site name was changed. |
| Tracker record retention settings were changed. |
| Anonymous user access settings were changed. |
| Login screen settings were changed. |
| Custom login and logout modules were configured. |
| Designer translations were promoted. |
| Designer super-user access was removed. |
| The platform version was upgraded. |
Excel Fill Template Administration
| Description |
|---|---|
| An Excel fill template was uploaded. |
| An Excel fill template was downloaded. |
| An Excel fill template was deleted. |
Express Groups
| Description |
|---|---|
| An Express group was created. |
| An Express group was changed. |
| An Express group was deleted. |
| Express groups were promoted to another environment. |
Express Roles
| Description |
|---|---|
| An Express role was created. |
| An Express role was changed. |
| An Express role was deleted. |
| Express roles were promoted to another environment. |
Express Users
| Description |
|---|---|
| An Express user record was created. |
| An Express user record was changed. |
| An Express user record was deleted. |
| Express user records were exported. |
| Express user records were imported. |
| An Express user's temporary password was resent. |
| A Creator searched for an Express user. |
| An Express user logged in. |
| An Express user logged out. |
| An Express user account was locked out. |
Global Variables
| Description |
|---|---|
| A was created. |
| A global variable was changed. |
| A global variable was deleted. |
| A global variable was promoted to another environment. |
Managed Assets
| Description |
|---|---|
| An asset was uploaded. |
| An asset was downloaded. |
| An asset was deleted. |
| An asset folder was created. |
Modules
| Description |
|---|---|
| A module was created. |
| A module was deleted. |
| A module was duplicated. |
| A module was restored from a previous save. |
| A module was saved. Includes the prior component tree for diff comparison. |
| Module-level settings were changed. |
| Module access permissions were changed. |
| A translation setting was changed on a module. |
| Workflow settings on a module were changed. |
| A module's edit mode setting was changed. |
| A module transform was created. |
| A module transform was changed. |
| A module transform was deleted. |
| A module snippet was saved. |
Module Submissions
| Description |
|---|---|
| Module submission data was created. |
| Multiple module submissions were retrieved. |
| A single module submission was retrieved. |
| Merged submissions were retrieved. |
| Module and workflow submissions were retrieved. |
| Multiple module submissions were updated. |
| A single module submission was updated. |
| Multiple module submissions were deleted. |
| A single module submission was deleted. |
| A module submission was restored. |
PDF Template Administration
| Description |
|---|---|
| A PDF template was uploaded. |
| A PDF template was downloaded. |
| A PDF template was deleted. |
Single Sign-On (SSO)
| Description |
|---|---|
| An OIDC SSO configuration was created. |
| An OIDC SSO configuration was changed. |
| An OIDC SSO configuration was deleted. |
| A SAML SSO configuration was created. |
| A SAML SSO configuration was changed. |
| A SAML SSO configuration was deleted. |
| A Designer SSO configuration was previewed. |
| An Express SSO configuration was previewed. |
Smart Components
Smart Component audit events require UnqorkAI (9.0.0 and later).
| Description |
|---|---|
| A Smart Component was created. |
| A Smart Component was published. Includes the prior definition for diff comparison. |
| A Smart Component was deleted. |
| A Smart Component's visibility was changed between public and private. |
| Smart Components were promoted between environments. |
Start Node Administration
| Description |
|---|---|
| A workflow start node was started. |
| A workflow start node was stopped. |
Style Administration
| Description |
|---|---|
| A style was changed. |
| A style was set as the default. |
| A style's default setting was removed. |
| A style was promoted to another environment. |
Themes
Theme audit events require UnqorkAI (9.0.0 and later).
| Description |
|---|---|
| A Theme was created. |
| A Theme's variables or settings were changed. |
| A Theme was deleted. |
| A Theme was promoted between environments. |
LLM Credentials and Service Administration
LLM Credential audit events require UnqorkAI (9.0.0 and later).
| Description |
|---|---|
| A service configuration was created. |
| A service configuration was changed. |
| A service configuration was deleted. |
The
service-administrationevent action covers all service-level configurations, including LLM Credentials, Integration Gateway services, and others. Filter byobject.attributesfields in the event payload to isolate events for a specific service type.
Workflow Submissions
| Description |
|---|---|
| Multiple workflow submissions were retrieved. |
| A single workflow submission was retrieved. |
| Module and workflow submissions were retrieved. |
| A single workflow submission was updated. |
| Multiple workflow submissions were deleted. |
| A single workflow submission was deleted. |
| A workflow submission was restored. |
Workspaces
| Description |
|---|---|
| A workspace was created. |
| A workspace's settings were changed. |
| A workspace was deleted. |
| A workspace was viewed. |
| A Creator was added to a workspace. |
| A Creator was removed from a workspace. |
| A data model was created in a workspace. |
| A data model was changed. |
| A data model was deleted. |
| A data model was archived. |
| A JSON schema was added to a data model. |
| A data model's JSON schema was changed. |
| A data model's JSON schema was deleted. |
| A data model's JSON schema was archived. |
| Records were exported from Record Collections. |
| Records were imported into Record Collections. |
Application Versioning
Application Versioning audit events require the Branch & Merge Beta.
| Description |
|---|---|
| A branch was created. |
| A branch's settings were changed. |
| A branch was discarded. |
| A branch was removed. |
| A pull request was submitted for review. |
| A pull request was approved. |
| A pull request was rejected. |
| A pull request was cancelled. |
| A branch was merged. |
Bring Your Own Component (BYO)
| Description |
|---|---|
| A BYO component package was installed. |
| A BYO component package was uninstalled. |
| A BYO component package was verified. |
Comments
| Description |
|---|---|
| A comment was created. |
| A comment was changed. |
| A comment was deleted. |
Search Configuration
| Description |
|---|---|
| A search configuration was created. |
| A search configuration was changed. |
| A search configuration was retrieved. |
| Multiple search configurations were retrieved. |
| A search configuration was archived. |
| A search configuration was removed. |
| A search was executed. |
Workflow Access
| Description |
|---|---|
| A workflow was accessed. |
| A workflow execution was triggered. |
Querying Audit Logs
Endpoint: GET /logs/audit-logs
Access: Designer Administrator only.
Query Parameters
Parameter | Required | Description |
|---|---|---|
| Yes | The start of the query window in ISO 8601 format. Seconds and milliseconds must be |
| Yes | The end of the query window in ISO 8601 format. Seconds and milliseconds must be |
| No | When |
| No | The event schema version to use. Defaults to |
The query window must not exceed one hour, and start time must be before end time.
Example request:
GET /logs/audit-logs?startDatetime=2026-04-13T10:00:00.000Z&endDatetime=2026-04-13T11:00:00.000Z
Both startDatetime and endDatetime must be set to the exact minute — seconds and milliseconds must be 0. The window in this example is exactly one hour, which is the maximum allowed.
Response
{
"logLocations": ["string"]
}
The response returns an array of signed URLs pointing to the log files for the requested time window. Each URL expires 15 minutes after the response is returned. Log files are stored in gzip (.gz) format — set unzip: true to receive decompressed content.
Changelog
Date | Change |
|---|---|
2026-09-11 | Expanded Logged Events to include all eventAction categories; added payload schema sub-articles (EN-8100). |
2026-09-11 | Full rewrite — added eventAction values for all existing categories; added Smart Components, Themes, and LLM Credentials sections (EN-8100). |
— | Initial publication. |