---
title: "Audit Log"
description: "Read the Incident Management audit trail: who created, changed or deleted which team, schedule, source or setting, with the recorded diff. Cursor-paginated."
---

`GET /api/im/audit-log`

Returns the Incident Management audit trail of your organization, newest first: every create, update and delete on teams, members, schedules, overrides, escalation tiers, alert sources, routing rules, channels and IM settings, with who did it and the recorded change.

## Authentication

Requires IM access **and** the organization role `admin`. Editors and responders are refused. An organization-wide API token works if it was created by an organization admin (a token carries the role of the user who created it). Incident Management must be enabled for the organization.

## Query Parameters

| Parameter | Type | Description |
|-----------|------|-------------|
| `entityType` | string | Only this entity type, e.g. `im_team`, `im_team_member`, `im_schedule`, `im_schedule_override`, `im_escalation_tier`, `im_alert_source`, `im_routing_rule`, `im_channel`, `im_incident`, `im_org_settings`. |
| `actor` | string | Only entries by this user ID. |
| `from` | ISO 8601 | Only entries at or after this instant. An invalid date is ignored. |
| `to` | ISO 8601 | Only entries at or before this instant. An invalid date is ignored. |
| `limit` | number | Page size. Default 50, maximum 200. |
| `before` | number | Cursor: pass `nextCursor` from the previous page to continue. |

## Example (cURL)

```bash
curl "$BASE_URL/api/im/audit-log?entityType=im_alert_source&limit=2" \
  -H "Authorization: Bearer $TOKEN"
```

## Response

```json
{
  "entries": [
    {
      "id": 5812,
      "entityType": "im_alert_source",
      "entityId": "7",
      "action": "update",
      "diff": { "ingestToken": { "from": "rotated", "to": "rotated" }, "secondaryExpiresAt": { "from": null, "to": "2026-10-16T09:30:00.000Z" } },
      "at": "2026-10-09T09:30:00.000Z",
      "actorUserId": "u_abc123",
      "actorName": "Jana Weber"
    },
    {
      "id": 5790,
      "entityType": "im_alert_source",
      "entityId": "7",
      "action": "create",
      "diff": { "name": "Zabbix production", "type": "zabbix", "teamId": 3, "autoResolve": true },
      "at": "2026-10-01T08:00:00.000Z",
      "actorUserId": "u_abc123",
      "actorName": "Jana Weber"
    }
  ],
  "hasMore": true,
  "nextCursor": 5790
}
```

| Field | Description |
|-------|-------------|
| `action` | `create`, `update` or `delete`. |
| `diff` | Free-form object recorded with the change, usually `{ field: { from, to } }` for updates. Secrets are never recorded, rotations appear as `"rotated"` or `"set"`. |
| `actorUserId`, `actorName` | Who made the change. Both `null` if that user account has been deleted since. |
| `hasMore`, `nextCursor` | When `hasMore` is `true`, request the next page with `before=<nextCursor>`. `nextCursor` is `null` on the last page. |

## Common errors

- `401 Unauthorized` (`unauthorized`) when not authenticated
- `403 Forbidden` (`customerScopedTokenForbidden`) for a customer-scoped token
- `403 Forbidden` (`imAccessDenied`) when the session has no IM-eligible role
- `403 Forbidden` (`imNotEnabled`) when Incident Management is not enabled for the organization
- `403 Forbidden` (`imAuditLogAccessDenied`) when the caller's role is not `admin`
