Incident management
Audit Log
Read the Incident Management audit trail: who created, changed or deleted which team, schedule, source or setting, with the recorded diff. Cursor-paginated.
GET /api/im/audit-log
Returns the Incident Management audit trail of your organization, newest first: every create, update and delete on teams, members, schedules, overrides, escalation tiers, alert sources, routing rules, channels and IM settings, with who did it and the recorded change.
Authentication
Requires IM access and the organization role admin. Editors and responders are refused. An organization-wide API token works if it was created by an organization admin (a token carries the role of the user who created it). Incident Management must be enabled for the organization.
Query Parameters
| Parameter | Type | Description |
|---|---|---|
entityType | string | Only this entity type, e.g. im_team, im_team_member, im_schedule, im_schedule_override, im_escalation_tier, im_alert_source, im_routing_rule, im_channel, im_incident, im_org_settings. |
actor | string | Only entries by this user ID. |
from | ISO 8601 | Only entries at or after this instant. An invalid date is ignored. |
to | ISO 8601 | Only entries at or before this instant. An invalid date is ignored. |
limit | number | Page size. Default 50, maximum 200. |
before | number | Cursor: pass nextCursor from the previous page to continue. |
Example (cURL)
curl "$BASE_URL/api/im/audit-log?entityType=im_alert_source&limit=2" \
-H "Authorization: Bearer $TOKEN"Response
{
"entries": [
{
"id": 5812,
"entityType": "im_alert_source",
"entityId": "7",
"action": "update",
"diff": { "ingestToken": { "from": "rotated", "to": "rotated" }, "secondaryExpiresAt": { "from": null, "to": "2026-10-16T09:30:00.000Z" } },
"at": "2026-10-09T09:30:00.000Z",
"actorUserId": "u_abc123",
"actorName": "Jana Weber"
},
{
"id": 5790,
"entityType": "im_alert_source",
"entityId": "7",
"action": "create",
"diff": { "name": "Zabbix production", "type": "zabbix", "teamId": 3, "autoResolve": true },
"at": "2026-10-01T08:00:00.000Z",
"actorUserId": "u_abc123",
"actorName": "Jana Weber"
}
],
"hasMore": true,
"nextCursor": 5790
}| Field | Description |
|---|---|
action | create, update or delete. |
diff | Free-form object recorded with the change, usually { field: { from, to } } for updates. Secrets are never recorded, rotations appear as "rotated" or "set". |
actorUserId, actorName | Who made the change. Both null if that user account has been deleted since. |
hasMore, nextCursor | When hasMore is true, request the next page with before=<nextCursor>. nextCursor is null on the last page. |
Common errors
401 Unauthorized(unauthorized) when not authenticated403 Forbidden(customerScopedTokenForbidden) for a customer-scoped token403 Forbidden(imAccessDenied) when the session has no IM-eligible role403 Forbidden(imNotEnabled) when Incident Management is not enabled for the organization403 Forbidden(imAuditLogAccessDenied) when the caller's role is notadmin