Browse documentation

Audit log

A 90-day record of what the app did and who acted on a finding.

Why. A finding nobody can account for later is not evidence. The Audit Log tab records app events for 90 days, so “who dismissed that finding, and when” has an answer.

You can filter by user, event type and details, and export the page to CSV — Time, Account ID, Event Type, Event Details. That export is what goes into an evidence pack for an audit. When more events match than the screen will show, the page says so rather than letting you export a prefix believing it is the whole range.

Events are stored one row per event in Forge SQL and deleted after 90 days. There is no cap on how many a day may hold — a busy day is exactly when the log has to keep recording.

What is recorded: settings changes, the scanner being switched on or off, each dismissal, restore, resolution and redaction, bulk scans starting and finishing, and each pattern, rule or category being added, removed or toggled. Findings and dismissals evicted at their storage cap are recorded too, so a queue that quietly stopped growing has an explanation.

No outbound notifications
Secret Scanner sends nothing outside your Atlassian tenant — there is no webhook and no external address in its manifest at all. That is what earns it Atlassian's Runs on Atlassian badge, and for an app that reads credentials out of your issues we thought that mattered more than pushing events to a chat channel. To act on a finding automatically, have Automation for Jira watch the issues the app creates or the label it applies.

Something missing or wrong on this page? Tell us in the support portal or email contact@synapseoasis.com.