Merchant & operations
Audit log
Investigate staff, customer and system actions with the append-only audit log, its filters, redaction, retention and CSV export.
On this page
What the audit log records
The audit log is the operational and security trail of a store. Use it to find out who did what, through which request, and with what result. It is not a debug log, and it does not record every read-only page view.
Open Admin → Audit logs. The list, the detail page and the CSV export all require the audit.view permission. The screens are Audit/Index and Audit/Show.
Fields of an entry
| Field | Content |
|---|---|
event_id |
Unique UUID for the entry |
created_at |
Time of the event |
actor_type, actor_id |
The staff user, customer or system that acted |
action |
Dotted action name, for example billing.renewal_consolidated |
category |
auth, security, commerce, payment, refund, webhook, support, privacy, notification, admin or system |
severity |
info, warning or critical |
outcome |
success, failure, denied or pending |
subject_type, subject_id |
The affected record, such as an order, payment, customer or ticket |
properties |
Event data, after redaction |
before, after |
Optional snapshots for a change, after redaction |
context |
Source (http, console or system), route, method, path and locale |
request_id, correlation_id |
Identifiers that link entries to one request or one longer flow |
route, method, status_code, ip, user_agent |
HTTP details when the action came from a request |
integrity_hash |
SHA-256 over the stored fields |
When the calling code does not set them, Agovena derives the category from the action prefix and the outcome from the action name. Severity follows from both: a failed or denied auth.* or security.* action is critical, other failures and denials are warning, and security, payment and refund actions default to warning. See AuditLogger.
Request and correlation IDs
Agovena reuses an incoming X-Request-ID or X-Correlation-ID header, or generates a UUID for each request. All entries written during the same request share these values. Code can also pass an explicit correlation ID to tie a checkout, webhook, job or support case together across requests.
Investigate an incident
- Search for a request ID to see everything one HTTP request wrote.
- Search for a correlation ID to follow a checkout, webhook or job across requests.
- Filter on object type and ID to see the history of one order, payment, customer or ticket.
- Narrow the list with category, severity, outcome, actor, action, method, IP and a date range.
- Open the entry for properties, before and after snapshots, technical context and the integrity check.
- Export the filtered set as CSV for offline analysis or a support file.
The search field also matches event IDs, actor and object IDs, IP addresses and the redacted event data. Filters are applied by AuditLogQuery. The CSV export uses the same filters and prefixes cells that start with =, +, - or @ so spreadsheet software does not run them as formulas.
Redaction
Audit data must never contain secrets. Before storage, Agovena replaces values with [REDACTED] when their key contains, among others, password, secret, token, authorization, cookie, api_key, private_key, connection_string, credential, card_number, pan, cvv, cvc, otp, recovery_code, email, phone, address, customer_name or full_name. This applies to nested values in properties, snapshots and context.
Values are also checked by content: bearer tokens, PEM private keys and key patterns such as sk_, pk_, test_ and live_ followed by a long string are redacted. Non-secret identifiers such as order IDs, amounts, currencies and provider references stay readable.
Integrity and retention
Entries are append-only. The AuditLog model refuses updates and deletes. The detail page recomputes the SHA-256 hash and shows Hash valid when it matches. Every other result is shown as Unavailable for legacy entry: that covers entries created before the extended audit migration, which have no hash, but also an entry whose hash no longer matches. Treat that label on a recent entry as a reason to investigate. The hash is not keyed, so it detects accidental or careless edits, not a deliberate change by someone with database write access who also recomputes the hash.
php artisan agovena:prune-logs runs daily from the scheduler and deletes audit entries older than AGOVENA_AUDIT_LOG_RETENTION days. The default is 365. Set a retention period that matches your legal and operational requirements, and include the audit table in your backups if you need older entries.