Audit logs
See who read and changed what — the repository audit log, the organization audit log, and the enterprise audit log, and what you need to turn them on.
GitDB keeps three audit views:
| Audit log | Where | What it shows |
|---|---|---|
| Repository | The repository's Settings → Audit log (under Security) | Every read and write recorded for that repository |
| Organization | The organization's Settings → Audit log | Organization activity: member, repository, and settings changes |
| Enterprise | The enterprise console's Audit log tab | Events across all of the enterprise's organizations |
Turning audit on
Audit is an enterprise capability, controlled by Enterprise Audit in the organization's Enterprise settings: "Record a per-file audit trail of every member's reads and writes, and detect bulk-read anomalies."
- It works only when your plan includes it and the organization owner has clicked Enable. If your plan doesn't include it, the setting says "Not included in your current plan — contact sales to enable it."
- Recording starts when it's enabled. Reads and writes made while it was off aren't in the log.
- An enterprise can enforce audit for all of its organizations with the Require audit policy.
Repository audit log
"Every read and write recorded for this repository — actor, operation, target, and outcome. Visible to owners and admins."
Open the repository's Settings → Audit log. The table shows Time, Actor, Principal, Operation, Target, and Outcome. Outcomes other than a success are shown in red, which makes refused reads and writes easy to spot.
To narrow the list:
- Enter an Operation (for example
read,push, oracl_create), a Target prefix (for examplesrc/orsecrets/), or both. - Pick a Limit: 50, 100 (default), 250, or 500 entries.
- Click APPLY.
Then type in Search loaded entries… to filter the rows already loaded by actor, principal, operation, target, or outcome.
Reads refused by a read access rule are recorded too.
Organization audit log
Owners and admins open the organization's Settings → Audit log: "Recent organization activity
across <org> — member, repository, and settings changes." Each entry shows the event type, its
target, who did it, the IP address when known, and the time.
If audit isn't available to you, the page says: "The audit log is an enterprise capability available to organization owners and admins once enabled for your plan."
Enterprise audit log
Enterprise owners and admins open the enterprise console's Audit log tab (Audit log (all orgs)). It lists the newest events across every organization in the enterprise, each with its event type, target, organization, and time. See Enterprise.
Access control
Restrict who can read which files with read access rules, for one repository or across a whole organization.
AST indexing
Index a repository's code structure so agents can search it by symbol and by meaning — what data is shared, how consent works, manual versus automatic indexing, and what each status means.