Haijun Platform Docs
ID

Compliance API › Activities

Query compliance activities

GET /v1/compliance/activities

List compliance activities for the authenticated tenant.

The tenant is the caller's parent organization, or — for an organization with no parent — the organization itself. Returns a paginated list of compliance activities that can be filtered by various criteria.

Query parameters

  • activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more

Filter activities by type. See the response data schema for the additional fields each type returns. Cannot be combined with exclude_activity_types[].

  • "abuse_decision_received"

An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.

  • "account_deleted"

User-initiated self-service account deletion.

  • "admin_api_key_created"

An admin API key was created.

  • "admin_api_key_deleted"

An admin API key was deleted.

  • "admin_api_key_updated"

An admin API key was updated (renamed or activated/deactivated).

  • "admin_connector_request_resolved"

Admin approved or dismissed pending member requests to enable an MCP connector.

  • "admin_request_created"

Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).

  • "admin_setup_checklist_step_delegated"

A step of the Haijun Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.

  • "admin_setup_checklist_step_delegation_cancelled"

The delegation of a Haijun Enterprise admin setup checklist step was cancelled.

  • "age_verified"

User age was verified.

  • "anonymous_mobile_login_attempted"

Anonymous mobile login was attempted.

  • "api_key_created"

Activity logged when a new API key is created.

  • "audit_log_export_accessed"

Audit log export file was accessed/downloaded via signed URL.

  • "audit_log_export_started"

Audit log export was initiated.

  • "billing_emails_updated"

The organization's billing email recipients were updated.

  • "ccr_agent_created"

A Haijun Code agent was created.

  • "ccr_agent_deleted"

A Haijun Code agent was deleted.

  • "ccr_agent_proxy_juglow_oidc_token_exchanged"

The Haijun Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.

  • "ccr_agent_proxy_juglow_oidc_token_minted"

The Haijun Code agent proxy minted a short-lived identity token for an juglow_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.

  • "ccr_agent_proxy_credential_created"

A Haijun Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Haijun Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.

  • "ccr_agent_proxy_credential_deleted"

A Haijun Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.

  • "ccr_agent_proxy_credential_rotated"

A Haijun Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.

  • "ccr_agent_proxy_credential_updated"

A Haijun Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.

  • "ccr_agent_proxy_destination_deleted"

An agent proxy destination was deleted.

  • "ccr_agent_proxy_network_events_listed"

A Haijun Code network activity export was accessed for the given hour.

  • "ccr_agent_proxy_profile_bound"

A Haijun Code agent proxy profile was bound to a scope, applying its policy to Haijun Code sessions in that scope.

  • "ccr_agent_proxy_profile_created"

A Haijun Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.

  • "ccr_agent_proxy_profile_deleted"

A Haijun Code agent proxy profile was deleted, removing its policy from everything it was bound to.

  • "ccr_agent_proxy_profile_unbound"

A Haijun Code agent proxy profile was unbound from a scope, removing its policy from Haijun Code sessions in that scope.

  • "ccr_agent_proxy_profile_updated"

A Haijun Code agent proxy profile's configuration was updated.

  • "ccr_agent_proxy_provisioning_credential_rejected"

An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.

  • "ccr_agent_proxy_provisioning_link_enabled"

An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.

  • "ccr_agent_proxy_provisioning_link_generated"

An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.

  • "ccr_agent_proxy_provisioning_link_revoked"

An organization owner revoked an unfilled agent proxy provisioning link.

  • "ccr_agent_proxy_provisioning_link_submitted"

A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.

  • "ccr_agent_proxy_rule_created"

An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.

  • "ccr_agent_proxy_rule_deleted"

An agent proxy rule was deleted.

  • "ccr_agent_proxy_rule_updated"

An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.

  • "ccr_agent_slack_access_scope_created"

A Haijun Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.

  • "ccr_agent_slack_access_scope_deleted"

A Haijun Code agent's access to an additional Slack channel was revoked.

  • "ccr_agent_slack_binding_created"

A Haijun Code agent was assigned to a Slack channel or workspace as its dedicated agent.

  • "ccr_agent_slack_binding_deleted"

A Haijun Code agent's assignment to a Slack channel or workspace was removed.

  • "ccr_agent_updated"

A Haijun Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.

  • "ccr_channel_manager_added"

An org owner/admin assigned an organization member to manage the Haijun-in-Slack configuration of one Slack channel.

  • "ccr_channel_manager_removed"

An org owner/admin removed an organization member's assignment to manage the Haijun-in-Slack configuration of one Slack channel.

  • "ccr_role_channel_assignment_deleted"

CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).

  • "ccr_role_channel_assignment_updated"

CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Haijun-in-Slack channel-manage surface.

  • "ccr_session_created"

A Haijun Code session was created. A session is one coding interaction with Haijun.

  • "ccr_session_deleted"

A Haijun Code session was deleted.

  • "ccr_session_updated"

A Haijun Code session's settings were updated.

  • "ccr_slack_channel_joined"

Haijun's Slack app joined a public Slack channel at an organization administrator's request.

  • "haijun_artifact_access_failed"

An attempt to access an artifact failed.

  • "haijun_artifact_commented"

Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.

  • "haijun_artifact_comments_viewed"

An artifact's comments were viewed.

  • "haijun_artifact_created"

An artifact was created.

  • "haijun_artifact_duplicated"

A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.

  • "haijun_artifact_external_sharing_permission_updated"

An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.

  • "haijun_artifact_invite_accepted"

Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by invitee_email and invitee_user_id.

  • "haijun_artifact_invite_created"

A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.

  • "haijun_artifact_invite_revoked"

A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.

  • "haijun_artifact_invite_role_updated"

A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.

  • "haijun_artifact_published"

A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as haijun_artifact_sharing_updated.

  • "haijun_artifact_sharing_updated"

An artifact's sharing settings were updated.

  • "haijun_artifact_viewed"

An artifact was viewed.

  • "haijun_chat_access_failed"

A user was denied access to a Haijun.ai chat conversation.

  • "haijun_chat_created"

User created a chat.

  • "haijun_chat_deleted"

A user deleted a Haijun.ai chat conversation.

  • "haijun_chat_deletion_failed"

A request to delete a Haijun.ai chat conversation failed.

  • "haijun_chat_settings_updated"

User updated the settings for a conversation.

  • "haijun_chat_snapshot_created"

User created/shared a chat snapshot.

  • "haijun_chat_snapshot_deleted"

User deleted/unshared a chat snapshot.

  • "haijun_chat_snapshot_viewed"

User viewed a chat snapshot (authenticated or public/unauthenticated).

  • "haijun_chat_sync_source_created"

A sync source was connected for syncing external content into Haijun chats.

  • "haijun_chat_sync_source_deleted"

A sync source was disconnected from Haijun chats.

  • "haijun_chat_sync_source_updated"

A Haijun chat sync source's configuration was updated.

  • "haijun_chat_updated"

User updated the chat metadata (e.g name, model).

  • "haijun_chat_viewed"

A user viewed a Haijun.ai chat conversation.

  • "haijun_code_credential_revoked"

A Haijun Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.

  • "haijun_code_review_config_updated"

Haijun Code Review configuration was enabled/disabled for an org.

  • "haijun_code_review_repository_added"

A repository was added to org-level Haijun Code Review configuration.

  • "haijun_code_review_repository_removed"

A repository was removed from org-level Haijun Code Review configuration.

  • "haijun_code_review_repository_updated"

A Haijun Code Review repository configuration was updated.

  • "haijun_code_runner_deleted"

A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.

  • "haijun_code_runner_pool_created"

A self-hosted runner pool for Haijun Code was created.

  • "haijun_code_runner_pool_deleted"

A self-hosted runner pool was deleted.

  • "haijun_code_runner_pool_secret_minted"

A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.

  • "haijun_code_runner_pool_session_queue_updated"

An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.

  • "haijun_code_runner_pool_updated"

A self-hosted runner pool's settings were updated.

  • "haijun_code_security_center_config_updated"

Haijun Code Security Center scanning was enabled/disabled for an org.

  • "haijun_code_security_scan_cancelled"

In-flight Haijun Code Security scans were cancelled for a project.

  • "haijun_code_security_scan_created"

A Haijun Code Security scan was started.

  • "haijun_code_security_scan_project_member_updated"

A person's access to a Haijun Code Security scan project was granted, changed, or revoked.

  • "haijun_code_security_scan_project_updated"

A Haijun Code Security scan project was archived, unarchived, created, or migrated to a new product experience.

  • "haijun_code_security_scan_project_visibility_updated"

A Haijun Code Security scan project was shared with the organization or made private.

  • "haijun_code_security_scan_run_updated"

A single Haijun Code Security scan run was archived, unarchived, or resumed after a billing pause.

  • "haijun_code_security_scan_schedule_deleted"

A recurring scan schedule was deleted for a Haijun Code Security project.

  • "haijun_code_security_scan_schedule_updated"

A recurring scan schedule was set or replaced for a Haijun Code Security project.

  • "haijun_code_security_vulnerability_deleted"

A Haijun Code Security vulnerability finding was permanently deleted.

  • "haijun_code_security_vulnerability_fix_session_created"

A Haijun Code remediation session was created for a Haijun Code Security vulnerability finding.

  • "haijun_code_security_vulnerability_updated"

A Haijun Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.

  • "haijun_code_security_webhook_created"

A Haijun Code Security outbound webhook was created.

  • "haijun_code_security_webhook_deleted"

A Haijun Code Security outbound webhook was deleted.

  • "haijun_code_security_webhook_secret_updated"

The HMAC signing secret for a Haijun Code Security webhook was rotated.

  • "haijun_code_security_webhook_updated"

A Haijun Code Security outbound webhook was updated.

  • "haijun_code_team_memory_acl_updated"

An RBAC group was added to or removed from the Haijun Code team-memory ACL.

  • "haijun_code_team_memory_updated"

Haijun Code team memory shared with the organization was updated.

  • "haijun_code_team_onboarding_guide_updated"

A Haijun Code team onboarding guide was created, updated, or deleted.

  • "haijun_code_user_marketplaces_updated"

A user's Haijun Code plugin marketplace selections were updated on Juglow servers.

  • "haijun_code_user_memory_updated"

A user's synced private Haijun Code memory was updated or deleted on Juglow servers.

  • "haijun_code_user_plugins_updated"

A user's Haijun Code plugin selections — which plugins are installed and enabled — were updated on Juglow servers.

  • "haijun_code_user_settings_updated"

A user's synced Haijun Code settings were updated or deleted on Juglow servers.

  • "haijun_command_created"

Command was created.

  • "haijun_command_deleted"

Command was deleted.

  • "haijun_command_replaced"

Command was replaced.

  • "haijun_enterprise_upgrade_credit_updated"

An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.

  • "haijun_file_access_failed"

A user was denied access to a file in Haijun.ai.

  • "haijun_file_deleted"

A file was deleted.

  • "haijun_file_exported"

A file was exported from Haijun to an external storage destination.

  • "haijun_file_uploaded"

A file was uploaded.

  • "haijun_file_viewed"

A user viewed a file in Haijun.ai.

  • "haijun_gdrive_integration_created"

A Google Drive integration was enabled for the organization.

  • "haijun_gdrive_integration_deleted"

A Google Drive integration was disabled for the organization.

  • "haijun_gdrive_integration_updated"

A Google Drive integration's configuration was updated.

  • "haijun_github_integration_created"

A GitHub integration was enabled for the organization.

  • "haijun_github_integration_deleted"

A GitHub integration was disabled for the organization.

  • "haijun_github_integration_updated"

A GitHub integration's configuration was updated.

  • "haijun_organization_settings_updated"

Organization settings were updated.

  • "haijun_plugin_archive_accessed"

A version archive of a member-owned plugin, containing that member's own files, was downloaded.

  • "haijun_plugin_created"

Plugin was created.

  • "haijun_plugin_deleted"

Plugin was deleted.

  • "haijun_plugin_disabled"

User disabled a plugin for their account.

  • "haijun_plugin_enabled"

User enabled a plugin for their account.

  • "haijun_plugin_replaced"

Plugin was replaced.

  • "haijun_plugin_security_scan_completed"

A security scan of a plugin completed and produced a verdict.

  • "haijun_plugin_updated"

Plugin was updated.

  • "haijun_project_archived"

A Haijun project was archived.

  • "haijun_project_created"

A Haijun project was created.

  • "haijun_project_deleted"

A Haijun project was deleted.

  • "haijun_project_document_access_failed"

An attempt to access a document in a Haijun project failed.

  • "haijun_project_document_bulk_deletion_audit_truncated"

A bulk request to delete documents from a Haijun project failed with more documents requested than were individually recorded in the audit log.

  • "haijun_project_document_deleted"

A document was deleted from a Haijun project.

  • "haijun_project_document_deletion_failed"

A request to delete a document from a Haijun project failed.

  • "haijun_project_document_updated"

The content of a document in a Haijun project was replaced in place.

  • "haijun_project_document_uploaded"

A document was uploaded to a Haijun project.

  • "haijun_project_document_viewed"

A document in a Haijun project was viewed.

  • "haijun_project_file_access_failed"

An attempt to access a file in a Haijun project failed.

  • "haijun_project_file_bulk_deletion_audit_truncated"

A bulk request to delete files from a Haijun project failed with more files requested than were individually recorded in the audit log.

  • "haijun_project_file_deleted"

A file was deleted from a Haijun project.

  • "haijun_project_file_deletion_failed"

A request to delete a file from a Haijun project failed.

  • "haijun_project_file_uploaded"

A file was uploaded to a Haijun project.

  • "haijun_project_reported"

A Haijun project was reported.

  • "haijun_project_sharing_updated"

A Haijun project's sharing settings were updated.

  • "haijun_project_sync_source_created"

A sync source was connected to a Haijun project's knowledge base.

  • "haijun_project_sync_source_deleted"

A sync source was disconnected from a Haijun project's knowledge base.

  • "haijun_project_sync_source_updated"

A Haijun project sync source's configuration was updated.

  • "haijun_project_viewed"

A Haijun project was viewed.

  • "haijun_published_artifact_deleted"

A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Juglow (for example, when it was removed for a policy violation).

  • "haijun_pubsec_identity_configured"

SAML IdP configuration updated for a public sector organization.

  • "haijun_skill_created"

Track was created.

  • "haijun_skill_deleted"

Track was deleted.

  • "haijun_skill_disabled"

User disabled a track for their account.

  • "haijun_skill_enabled"

User enabled a track for their account.

  • "haijun_skill_replaced"

Track was replaced.

  • "haijun_skill_security_scan_completed"

A security scan of a track completed and produced a verdict.

  • "haijun_user_role_updated"

A user's role within the organization was changed, or the user was added to or removed from the organization.

  • "haijun_user_seat_tier_updated"

An organization member's seat tier was changed. A null previous_seat_tier means the member previously had no seat assigned; a null current_seat_tier means the seat was removed.

  • "haijun_user_settings_updated"

User updated their personal settings.

  • "cli_plugin_exec_policy_updated"

Admin set or cleared the per-op permission ceiling for a plugin CLI.

  • "compliance_api_accessed"

Logging event auto-generated for each compliance API request.

  • "cowork_session_updated"

A Cowork session was updated.

  • "design_project_artifact_published"

A Haijun Design project's content was published as a haijun.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.

  • "design_project_created"

A Haijun Design project was created.

  • "design_project_deleted"

A Haijun Design project was deleted.

  • "design_project_member_added"

A member was granted access to a Haijun Design project.

  • "design_project_member_removed"

A member's access to a Haijun Design project was revoked.

  • "design_project_member_role_updated"

A Haijun Design project member's role was changed.

  • "design_project_published"

A Haijun Design template or design system was published, making it discoverable by everyone in its organization.

  • "design_project_sharing_updated"

A Haijun Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).

  • "design_project_unpublished"

A Haijun Design template or design system was unpublished, removing it from its organization's shared gallery.

  • "design_project_updated"

A Haijun Design project's metadata was updated.

  • "design_project_version_restored"

A Haijun Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.

  • "design_project_viewed"

A Haijun Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.

This activity type is retired: project content reads are no longer recorded. Events of this type may still appear in feeds for reads that occurred while it was active.

  • "desktop_extension_allowlisted"

A desktop extension was added to an org's allowlist.

  • "desktop_extension_blocklisted"

A desktop extension was added to the global blocklist.

  • "desktop_extension_deleted"

A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.

  • "desktop_extension_removed_from_allowlist"

A desktop extension was removed from an org's allowlist.

  • "desktop_extension_unblocked"

A desktop extension was removed from the global blocklist.

  • "desktop_extension_uploaded"

A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.

  • "desktop_extension_version_uploaded"

A new version of an existing org-owned desktop extension was uploaded.

  • "domain_claim_initiated"

Domain capture claim initiated over personal accounts on verified domains.

  • "end_user_invite_requested"

Non-admin member submitted an invite request for a new org member.

  • "extra_usage_billing_enabled"

Usage credit billing was enabled for an organization.

  • "extra_usage_credit_granted"

A promotional usage credit grant was claimed.

  • "extra_usage_spend_limit_created"

Usage credit spend limit was created.

  • "extra_usage_spend_limit_deleted"

Usage credit spend limit was deleted.

  • "extra_usage_spend_limit_increase_request_approved"

A usage credit spend limit increase request was approved.

  • "extra_usage_spend_limit_increase_request_denied"

A usage credit spend limit increase request was denied.

  • "extra_usage_spend_limit_updated"

Usage credit spend limit was updated.

  • "ghe_configuration_created"

Admin created a GHE configuration.

  • "ghe_configuration_deleted"

Admin deleted a GHE configuration.

  • "ghe_configuration_updated"

Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.

  • "ghe_user_connected"

User connected to a GHE instance.

  • "ghe_user_disconnected"

User disconnected from a GHE instance.

  • "ghe_webhook_signature_invalid"

Webhook signature validation failed.

  • "github_app_installation_linked"

An installation of the Haijun GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Haijun Code features act on that GitHub account's repositories.

  • "github_app_installation_unlinked"

An installation of the Haijun GitHub App was unlinked from the organization, so the organization's Haijun Code features can no longer act on that GitHub account's repositories through it.

  • "github_token_import"

A user attempted to import a personal GitHub access token for use with Haijun Code. The result field indicates the outcome of the import (imported, rejected, or failed).

  • "gitlab_configuration_created"

An organization admin created a self-managed GitLab configuration for syncing plugin marketplaces.

  • "gitlab_configuration_deleted"

An organization admin deleted a self-managed GitLab configuration.

  • "gitlab_configuration_updated"

An organization admin updated a self-managed GitLab configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.

  • "group_created"

A group was created (RBAC admin or SCIM provisioning).

  • "group_deleted"

A group was deleted (RBAC admin or SCIM provisioning).

  • "group_list_viewed"

Admin viewed the list of RBAC groups.

  • "group_member_added"

One or more members were added to a group.

  • "group_member_addition_failed"

A request to add members to a group failed. Some of the requested members may have been added before the failure.

  • "group_member_list_viewed"

Admin viewed the members of an RBAC group.

  • "group_member_removal_failed"

A request to remove members from a group failed. Some of the requested members may have been removed before the failure.

  • "group_member_removed"

One or more members were removed from a group.

  • "group_project_shares_revoked"

An RBAC group's project shares in one organization were revoked in bulk.

  • "group_skill_shares_revoked"

An RBAC group's track shares in one organization were revoked in bulk.

  • "group_updated"

A group was updated (RBAC admin or SCIM provisioning).

  • "group_viewed"

A group was viewed.

  • "group_visibility_updated"

An RBAC group's visibility policy was updated.

  • "inference_hooks_circuit_breaker_tripped"

The organization's Inference hooks circuit breaker tripped automatically: calls to the organization's Inference hooks endpoint crossed a failure threshold, and inspection was suspended to protect live traffic. While tripped, requests are handled according to the organization's failure handling setting — allowed through uninspected (fail open) or rejected (fail closed) — and no per-request Inference hooks activities are recorded. The tripped state persists until an administrator re-enables Inference hooks inspection (or explicitly resets the circuit breaker).

  • "inference_hooks_config_deleted"

Inference hooks configuration was removed for the organization.

  • "inference_hooks_config_updated"

Inference hooks configuration was created or updated for the organization.

  • "inference_hooks_request_denied"

Inference hooks inspection denied a request. The request was blocked and no model response was produced.

  • "inference_hooks_request_failed_open"

A request proceeded without Inference hooks inspection because a verdict could not be obtained and the organization's Inference hooks configuration is set to fail open.

  • "inference_hooks_signing_secret_generated"

A request signing secret was generated for the organization's Inference hooks configuration.

  • "integration_user_connected"

User connected to an integration.

  • "integration_user_disconnected"

User disconnected from an integration.

  • "invoice_collection_method_updated"

Invoice collection method was changed.

  • "lti_launch_initiated"

LTI launch was initiated.

  • "lti_launch_success"

LTI launch completed successfully.

  • "lti_platform_created"

Juglow staff created an LTI platform integration on behalf of an org.

  • "lti_platform_updated"

Juglow staff updated an LTI platform integration on behalf of an org.

  • "magic_link_login_failed"

A magic link sign-in attempt failed.

  • "magic_link_login_initiated"

A user requested a magic link sign-in email.

  • "magic_link_login_succeeded"

A user successfully signed in with a magic link email.

  • "managed_organization_setup_completed"

Managed (AWS Marketplace) organization setup was completed.

  • "marketplace_created"

Admin created an organization marketplace.

  • "marketplace_deleted"

Admin deleted an organization marketplace.

  • "marketplace_updated"

Admin updated an organization marketplace.

  • "marketplace_webhook_deleted"

Admin removed the GitHub push webhook for a marketplace.

  • "marketplace_webhook_provisioned"

Admin provisioned a GitHub push webhook for a marketplace.

  • "mcp_directory_server_published"

The organization published its approved MCP directory listing.

  • "mcp_server_created"

An MCP server was added to the organization.

  • "mcp_server_deleted"

An MCP server was removed from the organization.

  • "mcp_server_managed_auth_token_exchanged"

A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.

  • "mcp_server_managed_auth_updated"

An MCP server's enterprise managed authorization settings were set, changed, or cleared, including when they were supplied while the server was being added or edited. Fields without a "previous_" prefix describe the settings after the change and are null when the server has no managed authorization settings afterwards; "previous_" fields describe the settings before the change and are null when the server had none before (always the case for a newly added server).

  • "mcp_server_updated"

An MCP server's configuration was updated.

  • "mcp_tool_policy_updated"

The permission restriction for an MCP tool was set or cleared.

  • "org_analytics_api_capability_updated"

Organization analytics_api capability was enabled or disabled.

  • "org_bulk_delete_initiated"

Organization bulk deletion was initiated.

  • "org_capability_grant_added"

A capability grant was added to a workspace or role.

  • "org_capability_grant_removed"

A capability grant was removed from a workspace or role.

  • "org_haijun_code_data_sharing_disabled"

Organization Haijun Code data sharing was disabled.

  • "org_haijun_code_data_sharing_enabled"

Organization Haijun Code data sharing was enabled.

  • "org_haijun_code_desktop_disabled"

Organization Haijun Code Desktop was disabled.

  • "org_haijun_code_desktop_enabled"

Organization Haijun Code Desktop was enabled.

  • "org_haijun_code_zero_data_retention_disabled"

A primary owner disabled zero data retention for Haijun Code, so Haijun Code content is retained according to the organization's data retention settings.

  • "org_compliance_api_settings_updated"

Organization compliance API settings were updated.

  • "org_connector_domain_guard_updated"

Enterprise admin changed whether connectors are restricted to verified domains.

  • "org_cowork_act_without_asking_mode_disabled"

The "Act without asking" mode in Cowork was disabled for the organization, so members can no longer let Haijun act without asking for approval.

  • "org_cowork_act_without_asking_mode_enabled"

The "Act without asking" mode in Cowork was enabled for the organization, allowing members to let Haijun act without asking for approval.

  • "org_cowork_agent_disabled"

Organization Cowork Agent was disabled.

  • "org_cowork_agent_enabled"

Organization Cowork Agent was enabled.

  • "org_cowork_auto_mode_disabled"

The "Auto" permission mode in Cowork was disabled for the organization, so members can no longer let Haijun approve its own actions after a safety check.

  • "org_cowork_auto_mode_enabled"

The "Auto" permission mode in Cowork was enabled for the organization, allowing members to let Haijun approve its own actions after a safety check.

  • "org_cowork_browser_pane_disabled"

The in-app browser in Cowork was disabled for the organization, so Haijun can no longer open or use websites in a browser pane during members' Cowork sessions.

  • "org_cowork_browser_pane_enabled"

The in-app browser in Cowork was enabled for the organization, letting Haijun open and use websites in a browser pane during members' Cowork sessions.

  • "org_cowork_disabled"

Organization cowork was disabled.

  • "org_cowork_enabled"

Organization cowork was enabled.

  • "org_cowork_mcp_always_allow_disabled"

The "Always allow" option for connector tools in Cowork was disabled for the organization, so each use of a connector tool that can make changes requires approval. Read-only connector tools are not affected by this setting.

  • "org_cowork_mcp_always_allow_enabled"

The "Always allow" option for connector tools in Cowork was enabled for the organization, letting members approve a connector tool that can make changes once and allow its later uses automatically. Read-only connector tools are not affected by this setting.

  • "org_cowork_otlp_settings_updated"

The organization's Cowork OpenTelemetry monitoring export settings were updated.

  • "org_cowork_remote_disabled"

Running Cowork in the cloud was disabled for the organization, so members can no longer run Cowork sessions in Juglow-hosted remote environments.

  • "org_cowork_remote_enabled"

Running Cowork in the cloud was enabled for the organization, allowing members to run Cowork sessions in Juglow-hosted remote environments.

  • "org_creation_blocked"

Organization creation was blocked.

  • "org_data_export_accessed"

Organization data export file was accessed/downloaded via signed URL.

  • "org_data_export_completed"

Organization data export was completed.

  • "org_data_export_started"

Organization data export was started.

  • "org_data_residency_updated"

The organization's inference data residency settings were updated.

  • "org_deleted_via_bulk"

Organization was deleted via bulk operation.

  • "org_deletion_requested"

Organization deletion was requested.

  • "org_directory_resync_completed"

Organization directory resync completed successfully.

  • "org_directory_resync_failed"

Organization directory resync failed.

  • "org_directory_resync_started"

Organization directory resync was started asynchronously.

  • "org_directory_sync_activated"

Organization directory sync was activated.

  • "org_directory_sync_add_initiated"

Organization directory sync setup was initiated.

  • "org_directory_sync_deleted"

Organization directory sync was deleted.

  • "org_discoverability_disabled"

Admin disabled organization discoverability.

  • "org_discoverability_enabled"

Admin enabled organization discoverability.

  • "org_discoverability_settings_updated"

Admin updated organization discoverability settings.

  • "org_domain_add_initiated"

Organization domain verification was initiated.

  • "org_domain_removed"

Organization domain was removed.

  • "org_domain_verified"

Organization domain was verified.

  • "org_external_key_created"

A CMEK external key config was created.

  • "org_external_key_deleted"

A CMEK external key config was deleted.

  • "org_external_key_updated"

A CMEK external key config was updated.

  • "org_external_key_validated"

A CMEK external key config was validated against the customer's KMS.

  • "org_hipaa_self_serve_enabled"

A primary owner click-accepted the BAA and enabled HIPAA protections for the organization via the self-serve flow.

  • "org_invite_link_disabled"

Organization invite link was disabled.

  • "org_invite_link_generated"

Organization invite link was generated.

  • "org_invite_link_regenerated"

Organization invite link was regenerated (previous link invalidated).

  • "org_invite_viewed"

An organization invite was viewed.

  • "org_invites_listed"

Organization invites were listed.

  • "org_ip_restriction_created"

Organization IP restriction was created.

  • "org_ip_restriction_deleted"

Organization IP restriction was deleted.

  • "org_ip_restriction_updated"

Organization IP restriction was updated.

  • "org_join_proposal_decided"

Approve or reject decision on a parent-org join proposal.

  • "org_join_request_approved"

Admin approved a join request.

  • "org_join_request_created"

User requested to join an organization.

  • "org_join_request_dismissed"

Admin dismissed a join request.

  • "org_join_request_instant_approved"

Join request was instantly approved.

  • "org_join_requests_bulk_dismissed"

Admin bulk-dismissed join requests.

  • "org_magic_link_second_factor_toggled"

Organization magic link second factor was toggled.

  • "org_member_invites_disabled"

Admin disabled member invites for the organization.

  • "org_member_invites_enabled"

Admin enabled member invites for the organization.

  • "org_members_exported"

Organization members list was exported as CSV.

  • "org_model_default_updated"

An organization or role default model setting was changed by an administrator.

  • "org_parent_join_proposal_created"

Organization parent join proposal was created.

  • "org_parent_search_performed"

Organization parent search was performed.

  • "org_sso_add_initiated"

Organization SSO setup was initiated.

  • "org_sso_connection_activated"

Organization SSO connection was activated.

  • "org_sso_connection_deactivated"

Organization SSO connection was deactivated.

  • "org_sso_connection_deleted"

Organization SSO connection was deleted.

  • "org_sso_group_role_mappings_updated"

Organization SSO group role mappings were updated.

  • "org_sso_provisioning_mode_changed"

Organization SSO provisioning mode was changed.

  • "org_sso_scim_welcome_email_toggled"

Organization SCIM-provisioned welcome email was toggled.

  • "org_sso_seat_tier_assignment_toggled"

Organization SSO seat tier assignment was toggled.

  • "org_sso_seat_tier_mappings_updated"

Organization SSO seat tier mappings were updated.

  • "org_sso_toggled"

Organization SSO was toggled on or off.

  • "org_sync_deleting_synchronized_files_started"

Organization started deleting synchronized files.

  • "org_sync_synchronized_files_deleted"

Organization synchronized files were deleted.

  • "org_taint_added"

A taint was added to an organization.

  • "org_taint_removed"

A taint was removed from an organization.

  • "org_user_deleted"

User was removed from organization.

  • "org_user_invite_accepted"

Organization user invite was accepted.

  • "org_user_invite_deleted"

Organization user invite was deleted.

  • "org_user_invite_re_sent"

Organization user invite was re-sent.

  • "org_user_invite_rejected"

Organization user invite was rejected.

  • "org_user_invite_sent"

Organization user invite was sent.

  • "org_user_left"

User removed themselves from organization.

  • "org_user_shares_retained"

A member left or was removed from the organization while projects, tracks, plugins, or chats they had shared were still shared, and those shares were kept.

  • "org_user_trusted_devices_revoked"

An organization admin revoked a member's trusted devices and signed the member out of all active sessions.

  • "org_user_viewed"

An organization user was viewed.

  • "org_users_listed"

Organization users were listed.

  • "org_work_across_apps_disabled"

The organization's "Let Haijun work across apps" setting was turned off.

  • "org_work_across_apps_enabled"

The organization's "Let Haijun work across apps" setting was turned on.

  • "organization_address_updated"

The organization's billing or shipping address was updated.

  • "organization_icon_deleted"

Organization's custom icon deleted.

  • "organization_icon_updated"

Organization's custom icon uploaded or replaced.

  • "owned_projects_access_restored"

Access to owned projects was restored.

  • "payment_method_updated"

The organization's default payment method was updated.

  • "pending_share_created"

A pending share of a project or track was created for an email address that is not yet an organization member.

  • "pending_share_revoked"

A pending share of a project or track was revoked before the invitee joined the organization.

  • "phone_code_sent"

User requested a phone verification code.

  • "phone_code_verified"

User successfully verified their phone code.

  • "platform_agent_archived"

An agent was archived on the API platform.

  • "platform_agent_created"

An agent was created on the API platform.

  • "platform_agent_deleted"

An agent was deleted from the API platform.

  • "platform_agent_deployment_archived"

An agent deployment was archived on the API platform.

  • "platform_agent_deployment_created"

An agent deployment was created on the API platform.

  • "platform_agent_deployment_deleted"

An agent deployment was deleted from the API platform.

  • "platform_agent_deployment_paused"

An agent deployment was paused on the API platform.

  • "platform_agent_deployment_run_triggered"

An agent deployment was run on demand on the API platform.

  • "platform_agent_deployment_unpaused"

An agent deployment was resumed on the API platform.

  • "platform_agent_deployment_updated"

An agent deployment was updated on the API platform.

  • "platform_agent_session_archived"

An agent session was archived on the API platform.

  • "platform_agent_session_created"

An agent session was created on the API platform.

  • "platform_agent_session_deleted"

An agent session was deleted from the API platform.

  • "platform_agent_session_resource_added"

A resource was attached to an agent session.

  • "platform_agent_session_resource_deleted"

A resource attached to an agent session was removed.

  • "platform_agent_session_resource_updated"

A resource attached to an agent session was updated.

  • "platform_agent_session_thread_archived"

A thread within an agent session was archived.

  • "platform_agent_session_updated"

An agent session was updated on the API platform.

  • "platform_agent_updated"

An agent was updated on the API platform.

  • "platform_api_key_created"

An API key was created.

  • "platform_api_key_updated"

An API key was updated.

  • "platform_app_attest_authentication"

An attested mobile device attempted to exchange an Apple App Attest assertion for Juglow API credentials.

  • "platform_billing_upgraded_to_prepaid"

The organization's API billing was upgraded to the prepaid plan.

  • "platform_clearance_workspace_program_request_cleared"

A workspace's clearance program assignment was removed.

  • "platform_clearance_workspace_program_request_set"

A workspace's clearance program assignment was created or updated.

  • "platform_cost_report_viewed"

The cost report was viewed.

  • "platform_dream_archived"

A Dream (asynchronous memory-consolidation job) was archived.

  • "platform_dream_cancelled"

A Dream (asynchronous memory-consolidation job) was cancelled before it completed.

  • "platform_dream_created"

A Dream (asynchronous memory-consolidation job) was created.

  • "platform_federated_authentication"

A federated workload identity attempted to exchange an OIDC token for Juglow API credentials.

  • "platform_federation_issuer_archived"

An OIDC federation issuer was archived.

  • "platform_federation_issuer_created"

An OIDC federation issuer was created, registering an external identity provider that federation rules can trust for workload authentication.

  • "platform_federation_issuer_updated"

An OIDC federation issuer was updated.

  • "platform_federation_rule_archived"

An OIDC federation rule was archived.

  • "platform_federation_rule_created"

An OIDC federation rule was created, allowing tokens from a federation issuer to authenticate as a service account or user. Rules may additionally match on token claims or a condition expression, which are not included in this event.

  • "platform_federation_rule_updated"

An OIDC federation rule was updated.

  • "platform_federation_rule_workspace_added"

A federation rule was enabled for a workspace.

  • "platform_federation_rule_workspace_removed"

A federation rule was disabled for a workspace.

  • "platform_file_content_downloaded"

Activity logged when file content is downloaded via GET /v1/files/{file_id}/content.

  • "platform_file_deleted"

Activity logged when a file is deleted via DELETE /v1/files/{file_id}.

  • "platform_file_uploaded"

Activity logged when a file is uploaded via POST /v1/files.

  • "platform_memory_created"

An agent memory document was created.

  • "platform_memory_deleted"

An agent memory document was deleted.

  • "platform_memory_store_archived"

An agent memory store was archived. Archived stores reject new memory writes and cannot be attached to new sessions; deletion and redaction remain permitted for privacy scrubbing.

  • "platform_memory_store_created"

An agent memory store was created.

  • "platform_memory_store_deleted"

An agent memory store was deleted. Memory content removal may complete asynchronously for very large stores.

  • "platform_memory_store_updated"

An agent memory store's name, description, or metadata was updated.

  • "platform_memory_updated"

An agent memory document's content or path was updated.

  • "platform_memory_version_redacted"

A historical version of an agent memory document was redacted. Redaction scrubs the stored content of a specific version while preserving the version's existence in the history.

  • "platform_oauth_app_created"

An OAuth app was created.

  • "platform_oauth_app_revoked"

An OAuth app was revoked.

  • "platform_oauth_app_updated"

An OAuth app was updated.

  • "platform_plugin_directory_submission_created"

A plugin directory submission was created on the API platform. A plugin directory submission is a request to list a plugin in the public plugin directory.

  • "platform_plugin_directory_submission_deleted"

A plugin directory submission was deleted on the API platform.

  • "platform_plugin_directory_submission_updated"

A plugin directory submission was updated on the API platform.

  • "platform_service_account_archived"

A service account was archived.

  • "platform_service_account_created"

A service account was created.

  • "platform_service_account_updated"

A service account was updated.

  • "platform_service_account_workspace_member_added"

A service account was added as a member of a workspace.

  • "platform_service_account_workspace_member_removed"

A service account was removed from a workspace.

  • "platform_service_account_workspace_member_updated"

A service account's workspace membership role was updated.

  • "platform_signing_key_created"

Activity logged when a new request-signing key is registered for the org.

  • "platform_signing_key_deleted"

Activity logged when a signing key is permanently deleted.

  • "platform_signing_key_rotated"

Activity logged when an in-memory signing key is rotated.

  • "platform_skill_version_content_downloaded"

The content of a track version was downloaded through the Tracks API.

  • "platform_skill_version_created"

Activity logged when a track version is created via POST /v1/tracks/{skill_id}/versions.

  • "platform_skill_version_deleted"

Activity logged when a track version is deleted via DELETE /v1/tracks/{skill_id}/versions/{version}.

  • "platform_spend_limit_alert_emails_updated"

Spend limit alert email addresses and role targets were updated for an org.

  • "platform_spend_limit_created"

An org-level fixed-dollar spend limit was created.

  • "platform_spend_limit_deleted"

An org-level spend limit was removed.

  • "platform_spend_limit_updated"

An org-level spend limit snooze/ignore state was changed.

  • "platform_usage_report_haijun_code_viewed"

The Haijun Code usage report was viewed.

  • "platform_usage_report_messages_viewed"

The messages usage report was viewed.

  • "platform_workspace_archived"

A workspace was archived.

  • "platform_workspace_created"

A workspace was created.

  • "platform_workspace_inference_data_retention_disabled"

The zero data retention override was disabled for a workspace.

  • "platform_workspace_inference_data_retention_enabled"

The zero data retention override was enabled for a workspace.

  • "platform_workspace_member_added"

A member was added to a workspace.

  • "platform_workspace_member_removed"

A member was removed from a workspace.

  • "platform_workspace_member_updated"

A workspace member was updated.

  • "platform_workspace_member_viewed"

A workspace member was viewed.

  • "platform_workspace_members_listed"

Workspace members were listed.

  • "platform_workspace_rate_limit_deleted"

A workspace rate limit was deleted.

  • "platform_workspace_rate_limit_updated"

A workspace rate limit was created or updated.

  • "platform_workspace_updated"

A workspace was updated.

  • "plugin_installation_preference_updated"

An org admin changed the installation preference for a plugin.

  • "prepaid_auto_recharge_disabled"

Auto-recharge was disabled for API prepaid org.

  • "prepaid_auto_recharge_updated"

Auto-recharge settings were updated for API prepaid org.

  • "prepaid_extra_usage_auto_reload_disabled"

Prepaid usage credit auto-reload was disabled.

  • "prepaid_extra_usage_auto_reload_enabled"

Prepaid usage credit auto-reload was enabled.

  • "prepaid_extra_usage_auto_reload_settings_updated"

Prepaid usage credit auto-reload settings were updated.

  • "primary_owner_transferred"

Primary owner role was transferred to another org member.

  • "rbac_role_assigned"

Admin assigned an RBAC custom role to a principal.

  • "rbac_role_created"

Admin created an RBAC custom role.

  • "rbac_role_deleted"

Admin deleted an RBAC custom role.

  • "rbac_role_grant_updated"

Admin requested a capability grant for an RBAC custom role, or removed it.

Records the admin's change to the role. Whether the grant is currently in effect on the role is reported separately.

  • "rbac_role_permission_added"

Admin added a permission to an RBAC custom role.

Emitted once per requested permission, including permissions the role already had, so a retried request still produces a complete audit record.

  • "rbac_role_permission_removed"

Admin removed a permission from an RBAC custom role.

Emitted once per requested permission, including permissions the role already lacked, so a retried request still produces a complete audit record.

  • "rbac_role_unassigned"

Admin unassigned an RBAC custom role from a principal.

  • "rbac_role_updated"

Admin updated an RBAC custom role.

  • "role_assignment_granted"

Role assignment was granted.

  • "role_assignment_revoked"

Role assignment was revoked.

  • "scim_user_created"

A SCIM user was provisioned.

  • "scim_user_deleted"

A SCIM user was deleted.

  • "scim_user_updated"

A SCIM user was updated.

  • "scoped_api_key_deleted"

A scoped API key was deleted.

  • "scoped_api_key_updated"

A scoped API key was renamed or its activation state changed.

  • "seat_tier_changes_cancelled"

Scheduled seat tier downgrades were cancelled.

  • "seat_tiers_purchased"

Seat tiers were purchased or upgraded on a subscription.

  • "service_created"

Activity logged when an org service is explicitly created.

  • "service_deleted"

Activity logged when an org service is deleted.

  • "service_key_created"

Activity logged when a new org service key is created.

  • "service_key_revoked"

Activity logged when an org service key is revoked.

  • "session_revoked"

User revoked a specific session.

  • "session_share_accessed"

Session share was accessed.

  • "session_share_created"

Session share was created.

  • "session_share_revoked"

Session share was revoked.

  • "slack_workspace_claim_revoked"

A Slack workspace or Enterprise Grid organization was disconnected from the organization for Haijun in Slack.

  • "slack_workspace_claimed"

A Slack workspace or Enterprise Grid organization was connected to the organization for Haijun in Slack.

  • "social_login_succeeded"

A user successfully signed in with a social identity provider (Google, Apple, or Microsoft).

  • "sso_login_failed"

An SSO sign-in attempt failed.

  • "sso_login_initiated"

A user started an SSO sign-in flow.

  • "sso_login_succeeded"

A user successfully signed in with SSO.

  • "sso_second_factor_magic_link"

SSO second factor magic link was used.

  • "step_up_authentication_failed"

An additional identity check failed.

  • "step_up_authentication_succeeded"

The user completed an additional identity check to confirm a sensitive action.

  • "step_up_credential_enrolled"

A user enrolled a passkey for confirming sensitive actions on their account.

  • "subscription_cancellation_scheduled"

Subscription cancellation was scheduled at end of billing period.

  • "subscription_quantity_updated"

Contracted subscription seat quantity was updated.

  • "subscription_renewed"

A cancelled subscription was renewed.

  • "subscription_resumed"

A scheduled subscription cancellation was reversed.

  • "subscription_started"

A new subscription was created (Team or Enterprise).

  • "subscription_upgraded"

Subscription plan was upgraded (e.g. Team to Enterprise).

  • "trusted_device_credential_rotated"

The identity-verification credential of a trusted device was rotated to a new key.

  • "trusted_device_enrolled"

A device was enrolled as a trusted device for the user's account. Trusted devices can be used to confirm the user's identity for sensitive actions.

  • "trusted_device_revoked"

A trusted device was removed from the user's account.

  • "tunnel_archived"

An MCP tunnel was archived.

  • "tunnel_certificate_added"

An inner-TLS CA certificate was added to a tunnel.

  • "tunnel_certificate_revoked"

An inner-TLS CA certificate was revoked from a tunnel.

  • "tunnel_created"

An MCP tunnel was created.

  • "tunnel_token_minted"

An OAuth bearer token for the tunnel management API was minted.

  • "tunnel_token_revealed"

The Cloudflare connector secret for a tunnel was revealed to the caller.

  • "tunnel_token_revoked"

An OAuth bearer token for the tunnel management API was revoked.

  • "tunnel_token_rotated"

The Cloudflare connector secret for a tunnel was rotated.

tunnel_token_id is the id of the newly-issued token. The previous token is invalidated by the rotation and its id is not recorded here.

  • "user_consent_recorded"

User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).

  • "user_consent_revoked"

User revoked a previously granted consent for a specific entity.

  • "user_logged_out"

A user signed out of one or all sessions.

  • "verification_evidence_submitted"

Verification evidence was submitted for an organization's verification.

  • "verification_program_application_created"

An organization applied to a verification program.

  • "workspace_member_spend_limit_created"

A per-member or workspace-default Haijun Code spend limit was created.

  • "workspace_member_spend_limit_deleted"

A per-member or workspace-default Haijun Code spend limit was deleted.

  • "workspace_member_spend_limit_updated"

A per-member Haijun Code spend limit amount was updated.

  • "workspace_spend_limit_alert_emails_updated"

Spend limit alert email recipients were updated for a workspace.

  • "workspace_spend_limit_created"

A workspace-level API spend limit was created.

  • "workspace_spend_limit_deleted"

A workspace-level API spend limit was deleted.

  • actor_ids: optional array of string

Filter activities by actor IDs (currently only user_... IDs are supported). Enumerate IDs via GET /v1/compliance/organizations/{org_uuid}/users.

  • after_id: optional string

Pagination cursor for retrieving the next page of results. To paginate, pass the last_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • before_id: optional string

Pagination cursor for retrieving the previous page of results. To paginate, pass the first_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • created_at: optional object
  • gt: optional string

Filter activities created after this time (RFC 3339 format)

format: date-time

  • gte: optional string

Filter activities created at or after this time (RFC 3339 format)

format: date-time

  • lt: optional string

Filter activities created before this time (RFC 3339 format)

format: date-time

  • lte: optional string

Filter activities created at or before this time (RFC 3339 format)

format: date-time

  • exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more

Exclude activities of these types. Cannot be combined with activity_types[].

  • "abuse_decision_received"

An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.

  • "account_deleted"

User-initiated self-service account deletion.

  • "admin_api_key_created"

An admin API key was created.

  • "admin_api_key_deleted"

An admin API key was deleted.

  • "admin_api_key_updated"

An admin API key was updated (renamed or activated/deactivated).

  • "admin_connector_request_resolved"

Admin approved or dismissed pending member requests to enable an MCP connector.

  • "admin_request_created"

Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).

  • "admin_setup_checklist_step_delegated"

A step of the Haijun Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.

  • "admin_setup_checklist_step_delegation_cancelled"

The delegation of a Haijun Enterprise admin setup checklist step was cancelled.

  • "age_verified"

User age was verified.

  • "anonymous_mobile_login_attempted"

Anonymous mobile login was attempted.

  • "api_key_created"

Activity logged when a new API key is created.

  • "audit_log_export_accessed"

Audit log export file was accessed/downloaded via signed URL.

  • "audit_log_export_started"

Audit log export was initiated.

  • "billing_emails_updated"

The organization's billing email recipients were updated.

  • "ccr_agent_created"

A Haijun Code agent was created.

  • "ccr_agent_deleted"

A Haijun Code agent was deleted.

  • "ccr_agent_proxy_juglow_oidc_token_exchanged"

The Haijun Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.

  • "ccr_agent_proxy_juglow_oidc_token_minted"

The Haijun Code agent proxy minted a short-lived identity token for an juglow_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.

  • "ccr_agent_proxy_credential_created"

A Haijun Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Haijun Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.

  • "ccr_agent_proxy_credential_deleted"

A Haijun Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.

  • "ccr_agent_proxy_credential_rotated"

A Haijun Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.

  • "ccr_agent_proxy_credential_updated"

A Haijun Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.

  • "ccr_agent_proxy_destination_deleted"

An agent proxy destination was deleted.

  • "ccr_agent_proxy_network_events_listed"

A Haijun Code network activity export was accessed for the given hour.

  • "ccr_agent_proxy_profile_bound"

A Haijun Code agent proxy profile was bound to a scope, applying its policy to Haijun Code sessions in that scope.

  • "ccr_agent_proxy_profile_created"

A Haijun Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.

  • "ccr_agent_proxy_profile_deleted"

A Haijun Code agent proxy profile was deleted, removing its policy from everything it was bound to.

  • "ccr_agent_proxy_profile_unbound"

A Haijun Code agent proxy profile was unbound from a scope, removing its policy from Haijun Code sessions in that scope.

  • "ccr_agent_proxy_profile_updated"

A Haijun Code agent proxy profile's configuration was updated.

  • "ccr_agent_proxy_provisioning_credential_rejected"

An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.

  • "ccr_agent_proxy_provisioning_link_enabled"

An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.

  • "ccr_agent_proxy_provisioning_link_generated"

An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.

  • "ccr_agent_proxy_provisioning_link_revoked"

An organization owner revoked an unfilled agent proxy provisioning link.

  • "ccr_agent_proxy_provisioning_link_submitted"

A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.

  • "ccr_agent_proxy_rule_created"

An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.

  • "ccr_agent_proxy_rule_deleted"

An agent proxy rule was deleted.

  • "ccr_agent_proxy_rule_updated"

An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.

  • "ccr_agent_slack_access_scope_created"

A Haijun Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.

  • "ccr_agent_slack_access_scope_deleted"

A Haijun Code agent's access to an additional Slack channel was revoked.

  • "ccr_agent_slack_binding_created"

A Haijun Code agent was assigned to a Slack channel or workspace as its dedicated agent.

  • "ccr_agent_slack_binding_deleted"

A Haijun Code agent's assignment to a Slack channel or workspace was removed.

  • "ccr_agent_updated"

A Haijun Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.

  • "ccr_channel_manager_added"

An org owner/admin assigned an organization member to manage the Haijun-in-Slack configuration of one Slack channel.

  • "ccr_channel_manager_removed"

An org owner/admin removed an organization member's assignment to manage the Haijun-in-Slack configuration of one Slack channel.

  • "ccr_role_channel_assignment_deleted"

CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).

  • "ccr_role_channel_assignment_updated"

CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Haijun-in-Slack channel-manage surface.

  • "ccr_session_created"

A Haijun Code session was created. A session is one coding interaction with Haijun.

  • "ccr_session_deleted"

A Haijun Code session was deleted.

  • "ccr_session_updated"

A Haijun Code session's settings were updated.

  • "ccr_slack_channel_joined"

Haijun's Slack app joined a public Slack channel at an organization administrator's request.

  • "haijun_artifact_access_failed"

An attempt to access an artifact failed.

  • "haijun_artifact_commented"

Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.

  • "haijun_artifact_comments_viewed"

An artifact's comments were viewed.

  • "haijun_artifact_created"

An artifact was created.

  • "haijun_artifact_duplicated"

A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.

  • "haijun_artifact_external_sharing_permission_updated"

An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.

  • "haijun_artifact_invite_accepted"

Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by invitee_email and invitee_user_id.

  • "haijun_artifact_invite_created"

A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.

  • "haijun_artifact_invite_revoked"

A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.

  • "haijun_artifact_invite_role_updated"

A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.

  • "haijun_artifact_published"

A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as haijun_artifact_sharing_updated.

  • "haijun_artifact_sharing_updated"

An artifact's sharing settings were updated.

  • "haijun_artifact_viewed"

An artifact was viewed.

  • "haijun_chat_access_failed"

A user was denied access to a Haijun.ai chat conversation.

  • "haijun_chat_created"

User created a chat.

  • "haijun_chat_deleted"

A user deleted a Haijun.ai chat conversation.

  • "haijun_chat_deletion_failed"

A request to delete a Haijun.ai chat conversation failed.

  • "haijun_chat_settings_updated"

User updated the settings for a conversation.

  • "haijun_chat_snapshot_created"

User created/shared a chat snapshot.

  • "haijun_chat_snapshot_deleted"

User deleted/unshared a chat snapshot.

  • "haijun_chat_snapshot_viewed"

User viewed a chat snapshot (authenticated or public/unauthenticated).

  • "haijun_chat_sync_source_created"

A sync source was connected for syncing external content into Haijun chats.

  • "haijun_chat_sync_source_deleted"

A sync source was disconnected from Haijun chats.

  • "haijun_chat_sync_source_updated"

A Haijun chat sync source's configuration was updated.

  • "haijun_chat_updated"

User updated the chat metadata (e.g name, model).

  • "haijun_chat_viewed"

A user viewed a Haijun.ai chat conversation.

  • "haijun_code_credential_revoked"

A Haijun Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.

  • "haijun_code_review_config_updated"

Haijun Code Review configuration was enabled/disabled for an org.

  • "haijun_code_review_repository_added"

A repository was added to org-level Haijun Code Review configuration.

  • "haijun_code_review_repository_removed"

A repository was removed from org-level Haijun Code Review configuration.

  • "haijun_code_review_repository_updated"

A Haijun Code Review repository configuration was updated.

  • "haijun_code_runner_deleted"

A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.

  • "haijun_code_runner_pool_created"

A self-hosted runner pool for Haijun Code was created.

  • "haijun_code_runner_pool_deleted"

A self-hosted runner pool was deleted.

  • "haijun_code_runner_pool_secret_minted"

A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.

  • "haijun_code_runner_pool_session_queue_updated"

An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.

  • "haijun_code_runner_pool_updated"

A self-hosted runner pool's settings were updated.

  • "haijun_code_security_center_config_updated"

Haijun Code Security Center scanning was enabled/disabled for an org.

  • "haijun_code_security_scan_cancelled"

In-flight Haijun Code Security scans were cancelled for a project.

  • "haijun_code_security_scan_created"

A Haijun Code Security scan was started.

  • "haijun_code_security_scan_project_member_updated"

A person's access to a Haijun Code Security scan project was granted, changed, or revoked.

  • "haijun_code_security_scan_project_updated"

A Haijun Code Security scan project was archived, unarchived, created, or migrated to a new product experience.

  • "haijun_code_security_scan_project_visibility_updated"

A Haijun Code Security scan project was shared with the organization or made private.

  • "haijun_code_security_scan_run_updated"

A single Haijun Code Security scan run was archived, unarchived, or resumed after a billing pause.

  • "haijun_code_security_scan_schedule_deleted"

A recurring scan schedule was deleted for a Haijun Code Security project.

  • "haijun_code_security_scan_schedule_updated"

A recurring scan schedule was set or replaced for a Haijun Code Security project.

  • "haijun_code_security_vulnerability_deleted"

A Haijun Code Security vulnerability finding was permanently deleted.

  • "haijun_code_security_vulnerability_fix_session_created"

A Haijun Code remediation session was created for a Haijun Code Security vulnerability finding.

  • "haijun_code_security_vulnerability_updated"

A Haijun Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.

  • "haijun_code_security_webhook_created"

A Haijun Code Security outbound webhook was created.

  • "haijun_code_security_webhook_deleted"

A Haijun Code Security outbound webhook was deleted.

  • "haijun_code_security_webhook_secret_updated"

The HMAC signing secret for a Haijun Code Security webhook was rotated.

  • "haijun_code_security_webhook_updated"

A Haijun Code Security outbound webhook was updated.

  • "haijun_code_team_memory_acl_updated"

An RBAC group was added to or removed from the Haijun Code team-memory ACL.

  • "haijun_code_team_memory_updated"

Haijun Code team memory shared with the organization was updated.

  • "haijun_code_team_onboarding_guide_updated"

A Haijun Code team onboarding guide was created, updated, or deleted.

  • "haijun_code_user_marketplaces_updated"

A user's Haijun Code plugin marketplace selections were updated on Juglow servers.

  • "haijun_code_user_memory_updated"

A user's synced private Haijun Code memory was updated or deleted on Juglow servers.

  • "haijun_code_user_plugins_updated"

A user's Haijun Code plugin selections — which plugins are installed and enabled — were updated on Juglow servers.

  • "haijun_code_user_settings_updated"

A user's synced Haijun Code settings were updated or deleted on Juglow servers.

  • "haijun_command_created"

Command was created.

  • "haijun_command_deleted"

Command was deleted.

  • "haijun_command_replaced"

Command was replaced.

  • "haijun_enterprise_upgrade_credit_updated"

An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.

  • "haijun_file_access_failed"

A user was denied access to a file in Haijun.ai.

  • "haijun_file_deleted"

A file was deleted.

  • "haijun_file_exported"

A file was exported from Haijun to an external storage destination.

  • "haijun_file_uploaded"

A file was uploaded.

  • "haijun_file_viewed"

A user viewed a file in Haijun.ai.

  • "haijun_gdrive_integration_created"

A Google Drive integration was enabled for the organization.

  • "haijun_gdrive_integration_deleted"

A Google Drive integration was disabled for the organization.

  • "haijun_gdrive_integration_updated"

A Google Drive integration's configuration was updated.

  • "haijun_github_integration_created"

A GitHub integration was enabled for the organization.

  • "haijun_github_integration_deleted"

A GitHub integration was disabled for the organization.

  • "haijun_github_integration_updated"

A GitHub integration's configuration was updated.

  • "haijun_organization_settings_updated"

Organization settings were updated.

  • "haijun_plugin_archive_accessed"

A version archive of a member-owned plugin, containing that member's own files, was downloaded.

  • "haijun_plugin_created"

Plugin was created.

  • "haijun_plugin_deleted"

Plugin was deleted.

  • "haijun_plugin_disabled"

User disabled a plugin for their account.

  • "haijun_plugin_enabled"

User enabled a plugin for their account.

  • "haijun_plugin_replaced"

Plugin was replaced.

  • "haijun_plugin_security_scan_completed"

A security scan of a plugin completed and produced a verdict.

  • "haijun_plugin_updated"

Plugin was updated.

  • "haijun_project_archived"

A Haijun project was archived.

  • "haijun_project_created"

A Haijun project was created.

  • "haijun_project_deleted"

A Haijun project was deleted.

  • "haijun_project_document_access_failed"

An attempt to access a document in a Haijun project failed.

  • "haijun_project_document_bulk_deletion_audit_truncated"

A bulk request to delete documents from a Haijun project failed with more documents requested than were individually recorded in the audit log.

  • "haijun_project_document_deleted"

A document was deleted from a Haijun project.

  • "haijun_project_document_deletion_failed"

A request to delete a document from a Haijun project failed.

  • "haijun_project_document_updated"

The content of a document in a Haijun project was replaced in place.

  • "haijun_project_document_uploaded"

A document was uploaded to a Haijun project.

  • "haijun_project_document_viewed"

A document in a Haijun project was viewed.

  • "haijun_project_file_access_failed"

An attempt to access a file in a Haijun project failed.

  • "haijun_project_file_bulk_deletion_audit_truncated"

A bulk request to delete files from a Haijun project failed with more files requested than were individually recorded in the audit log.

  • "haijun_project_file_deleted"

A file was deleted from a Haijun project.

  • "haijun_project_file_deletion_failed"

A request to delete a file from a Haijun project failed.

  • "haijun_project_file_uploaded"

A file was uploaded to a Haijun project.

  • "haijun_project_reported"

A Haijun project was reported.

  • "haijun_project_sharing_updated"

A Haijun project's sharing settings were updated.

  • "haijun_project_sync_source_created"

A sync source was connected to a Haijun project's knowledge base.

  • "haijun_project_sync_source_deleted"

A sync source was disconnected from a Haijun project's knowledge base.

  • "haijun_project_sync_source_updated"

A Haijun project sync source's configuration was updated.

  • "haijun_project_viewed"

A Haijun project was viewed.

  • "haijun_published_artifact_deleted"

A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Juglow (for example, when it was removed for a policy violation).

  • "haijun_pubsec_identity_configured"

SAML IdP configuration updated for a public sector organization.

  • "haijun_skill_created"

Track was created.

  • "haijun_skill_deleted"

Track was deleted.

  • "haijun_skill_disabled"

User disabled a track for their account.

  • "haijun_skill_enabled"

User enabled a track for their account.

  • "haijun_skill_replaced"

Track was replaced.

  • "haijun_skill_security_scan_completed"

A security scan of a track completed and produced a verdict.

  • "haijun_user_role_updated"

A user's role within the organization was changed, or the user was added to or removed from the organization.

  • "haijun_user_seat_tier_updated"

An organization member's seat tier was changed. A null previous_seat_tier means the member previously had no seat assigned; a null current_seat_tier means the seat was removed.

  • "haijun_user_settings_updated"

User updated their personal settings.

  • "cli_plugin_exec_policy_updated"

Admin set or cleared the per-op permission ceiling for a plugin CLI.

  • "compliance_api_accessed"

Logging event auto-generated for each compliance API request.

  • "cowork_session_updated"

A Cowork session was updated.

  • "design_project_artifact_published"

A Haijun Design project's content was published as a haijun.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.

  • "design_project_created"

A Haijun Design project was created.

  • "design_project_deleted"

A Haijun Design project was deleted.

  • "design_project_member_added"

A member was granted access to a Haijun Design project.

  • "design_project_member_removed"

A member's access to a Haijun Design project was revoked.

  • "design_project_member_role_updated"

A Haijun Design project member's role was changed.

  • "design_project_published"

A Haijun Design template or design system was published, making it discoverable by everyone in its organization.

  • "design_project_sharing_updated"

A Haijun Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).

  • "design_project_unpublished"

A Haijun Design template or design system was unpublished, removing it from its organization's shared gallery.

  • "design_project_updated"

A Haijun Design project's metadata was updated.

  • "design_project_version_restored"

A Haijun Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.

  • "design_project_viewed"

A Haijun Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.

This activity type is retired: project content reads are no longer recorded. Events of this type may still appear in feeds for reads that occurred while it was active.

  • "desktop_extension_allowlisted"

A desktop extension was added to an org's allowlist.

  • "desktop_extension_blocklisted"

A desktop extension was added to the global blocklist.

  • "desktop_extension_deleted"

A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.

  • "desktop_extension_removed_from_allowlist"

A desktop extension was removed from an org's allowlist.

  • "desktop_extension_unblocked"

A desktop extension was removed from the global blocklist.

  • "desktop_extension_uploaded"

A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.

  • "desktop_extension_version_uploaded"

A new version of an existing org-owned desktop extension was uploaded.

  • "domain_claim_initiated"

Domain capture claim initiated over personal accounts on verified domains.

  • "end_user_invite_requested"

Non-admin member submitted an invite request for a new org member.

  • "extra_usage_billing_enabled"

Usage credit billing was enabled for an organization.

  • "extra_usage_credit_granted"

A promotional usage credit grant was claimed.

  • "extra_usage_spend_limit_created"

Usage credit spend limit was created.

  • "extra_usage_spend_limit_deleted"

Usage credit spend limit was deleted.

  • "extra_usage_spend_limit_increase_request_approved"

A usage credit spend limit increase request was approved.

  • "extra_usage_spend_limit_increase_request_denied"

A usage credit spend limit increase request was denied.

  • "extra_usage_spend_limit_updated"

Usage credit spend limit was updated.

  • "ghe_configuration_created"

Admin created a GHE configuration.

  • "ghe_configuration_deleted"

Admin deleted a GHE configuration.

  • "ghe_configuration_updated"

Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.

  • "ghe_user_connected"

User connected to a GHE instance.

  • "ghe_user_disconnected"

User disconnected from a GHE instance.

  • "ghe_webhook_signature_invalid"

Webhook signature validation failed.

  • "github_app_installation_linked"

An installation of the Haijun GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Haijun Code features act on that GitHub account's repositories.

  • "github_app_installation_unlinked"

An installation of the Haijun GitHub App was unlinked from the organization, so the organization's Haijun Code features can no longer act on that GitHub account's repositories through it.

  • "github_token_import"

A user attempted to import a personal GitHub access token for use with Haijun Code. The result field indicates the outcome of the import (imported, rejected, or failed).

  • "gitlab_configuration_created"

An organization admin created a self-managed GitLab configuration for syncing plugin marketplaces.

  • "gitlab_configuration_deleted"

An organization admin deleted a self-managed GitLab configuration.

  • "gitlab_configuration_updated"

An organization admin updated a self-managed GitLab configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.

  • "group_created"

A group was created (RBAC admin or SCIM provisioning).

  • "group_deleted"

A group was deleted (RBAC admin or SCIM provisioning).

  • "group_list_viewed"

Admin viewed the list of RBAC groups.

  • "group_member_added"

One or more members were added to a group.

  • "group_member_addition_failed"

A request to add members to a group failed. Some of the requested members may have been added before the failure.

  • "group_member_list_viewed"

Admin viewed the members of an RBAC group.

  • "group_member_removal_failed"

A request to remove members from a group failed. Some of the requested members may have been removed before the failure.

  • "group_member_removed"

One or more members were removed from a group.

  • "group_project_shares_revoked"

An RBAC group's project shares in one organization were revoked in bulk.

  • "group_skill_shares_revoked"

An RBAC group's track shares in one organization were revoked in bulk.

  • "group_updated"

A group was updated (RBAC admin or SCIM provisioning).

  • "group_viewed"

A group was viewed.

  • "group_visibility_updated"

An RBAC group's visibility policy was updated.

  • "inference_hooks_circuit_breaker_tripped"

The organization's Inference hooks circuit breaker tripped automatically: calls to the organization's Inference hooks endpoint crossed a failure threshold, and inspection was suspended to protect live traffic. While tripped, requests are handled according to the organization's failure handling setting — allowed through uninspected (fail open) or rejected (fail closed) — and no per-request Inference hooks activities are recorded. The tripped state persists until an administrator re-enables Inference hooks inspection (or explicitly resets the circuit breaker).

  • "inference_hooks_config_deleted"

Inference hooks configuration was removed for the organization.

  • "inference_hooks_config_updated"

Inference hooks configuration was created or updated for the organization.

  • "inference_hooks_request_denied"

Inference hooks inspection denied a request. The request was blocked and no model response was produced.

  • "inference_hooks_request_failed_open"

A request proceeded without Inference hooks inspection because a verdict could not be obtained and the organization's Inference hooks configuration is set to fail open.

  • "inference_hooks_signing_secret_generated"

A request signing secret was generated for the organization's Inference hooks configuration.

  • "integration_user_connected"

User connected to an integration.

  • "integration_user_disconnected"

User disconnected from an integration.

  • "invoice_collection_method_updated"

Invoice collection method was changed.

  • "lti_launch_initiated"

LTI launch was initiated.

  • "lti_launch_success"

LTI launch completed successfully.

  • "lti_platform_created"

Juglow staff created an LTI platform integration on behalf of an org.

  • "lti_platform_updated"

Juglow staff updated an LTI platform integration on behalf of an org.

  • "magic_link_login_failed"

A magic link sign-in attempt failed.

  • "magic_link_login_initiated"

A user requested a magic link sign-in email.

  • "magic_link_login_succeeded"

A user successfully signed in with a magic link email.

  • "managed_organization_setup_completed"

Managed (AWS Marketplace) organization setup was completed.

  • "marketplace_created"

Admin created an organization marketplace.

  • "marketplace_deleted"

Admin deleted an organization marketplace.

  • "marketplace_updated"

Admin updated an organization marketplace.

  • "marketplace_webhook_deleted"

Admin removed the GitHub push webhook for a marketplace.

  • "marketplace_webhook_provisioned"

Admin provisioned a GitHub push webhook for a marketplace.

  • "mcp_directory_server_published"

The organization published its approved MCP directory listing.

  • "mcp_server_created"

An MCP server was added to the organization.

  • "mcp_server_deleted"

An MCP server was removed from the organization.

  • "mcp_server_managed_auth_token_exchanged"

A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.

  • "mcp_server_managed_auth_updated"

An MCP server's enterprise managed authorization settings were set, changed, or cleared, including when they were supplied while the server was being added or edited. Fields without a "previous_" prefix describe the settings after the change and are null when the server has no managed authorization settings afterwards; "previous_" fields describe the settings before the change and are null when the server had none before (always the case for a newly added server).

  • "mcp_server_updated"

An MCP server's configuration was updated.

  • "mcp_tool_policy_updated"

The permission restriction for an MCP tool was set or cleared.

  • "org_analytics_api_capability_updated"

Organization analytics_api capability was enabled or disabled.

  • "org_bulk_delete_initiated"

Organization bulk deletion was initiated.

  • "org_capability_grant_added"

A capability grant was added to a workspace or role.

  • "org_capability_grant_removed"

A capability grant was removed from a workspace or role.

  • "org_haijun_code_data_sharing_disabled"

Organization Haijun Code data sharing was disabled.

  • "org_haijun_code_data_sharing_enabled"

Organization Haijun Code data sharing was enabled.

  • "org_haijun_code_desktop_disabled"

Organization Haijun Code Desktop was disabled.

  • "org_haijun_code_desktop_enabled"

Organization Haijun Code Desktop was enabled.

  • "org_haijun_code_zero_data_retention_disabled"

A primary owner disabled zero data retention for Haijun Code, so Haijun Code content is retained according to the organization's data retention settings.

  • "org_compliance_api_settings_updated"

Organization compliance API settings were updated.

  • "org_connector_domain_guard_updated"

Enterprise admin changed whether connectors are restricted to verified domains.

  • "org_cowork_act_without_asking_mode_disabled"

The "Act without asking" mode in Cowork was disabled for the organization, so members can no longer let Haijun act without asking for approval.

  • "org_cowork_act_without_asking_mode_enabled"

The "Act without asking" mode in Cowork was enabled for the organization, allowing members to let Haijun act without asking for approval.

  • "org_cowork_agent_disabled"

Organization Cowork Agent was disabled.

  • "org_cowork_agent_enabled"

Organization Cowork Agent was enabled.

  • "org_cowork_auto_mode_disabled"

The "Auto" permission mode in Cowork was disabled for the organization, so members can no longer let Haijun approve its own actions after a safety check.

  • "org_cowork_auto_mode_enabled"

The "Auto" permission mode in Cowork was enabled for the organization, allowing members to let Haijun approve its own actions after a safety check.

  • "org_cowork_browser_pane_disabled"

The in-app browser in Cowork was disabled for the organization, so Haijun can no longer open or use websites in a browser pane during members' Cowork sessions.

  • "org_cowork_browser_pane_enabled"

The in-app browser in Cowork was enabled for the organization, letting Haijun open and use websites in a browser pane during members' Cowork sessions.

  • "org_cowork_disabled"

Organization cowork was disabled.

  • "org_cowork_enabled"

Organization cowork was enabled.

  • "org_cowork_mcp_always_allow_disabled"

The "Always allow" option for connector tools in Cowork was disabled for the organization, so each use of a connector tool that can make changes requires approval. Read-only connector tools are not affected by this setting.

  • "org_cowork_mcp_always_allow_enabled"

The "Always allow" option for connector tools in Cowork was enabled for the organization, letting members approve a connector tool that can make changes once and allow its later uses automatically. Read-only connector tools are not affected by this setting.

  • "org_cowork_otlp_settings_updated"

The organization's Cowork OpenTelemetry monitoring export settings were updated.

  • "org_cowork_remote_disabled"

Running Cowork in the cloud was disabled for the organization, so members can no longer run Cowork sessions in Juglow-hosted remote environments.

  • "org_cowork_remote_enabled"

Running Cowork in the cloud was enabled for the organization, allowing members to run Cowork sessions in Juglow-hosted remote environments.

  • "org_creation_blocked"

Organization creation was blocked.

  • "org_data_export_accessed"

Organization data export file was accessed/downloaded via signed URL.

  • "org_data_export_completed"

Organization data export was completed.

  • "org_data_export_started"

Organization data export was started.

  • "org_data_residency_updated"

The organization's inference data residency settings were updated.

  • "org_deleted_via_bulk"

Organization was deleted via bulk operation.

  • "org_deletion_requested"

Organization deletion was requested.

  • "org_directory_resync_completed"

Organization directory resync completed successfully.

  • "org_directory_resync_failed"

Organization directory resync failed.

  • "org_directory_resync_started"

Organization directory resync was started asynchronously.

  • "org_directory_sync_activated"

Organization directory sync was activated.

  • "org_directory_sync_add_initiated"

Organization directory sync setup was initiated.

  • "org_directory_sync_deleted"

Organization directory sync was deleted.

  • "org_discoverability_disabled"

Admin disabled organization discoverability.

  • "org_discoverability_enabled"

Admin enabled organization discoverability.

  • "org_discoverability_settings_updated"

Admin updated organization discoverability settings.

  • "org_domain_add_initiated"

Organization domain verification was initiated.

  • "org_domain_removed"

Organization domain was removed.

  • "org_domain_verified"

Organization domain was verified.

  • "org_external_key_created"

A CMEK external key config was created.

  • "org_external_key_deleted"

A CMEK external key config was deleted.

  • "org_external_key_updated"

A CMEK external key config was updated.

  • "org_external_key_validated"

A CMEK external key config was validated against the customer's KMS.

  • "org_hipaa_self_serve_enabled"

A primary owner click-accepted the BAA and enabled HIPAA protections for the organization via the self-serve flow.

  • "org_invite_link_disabled"

Organization invite link was disabled.

  • "org_invite_link_generated"

Organization invite link was generated.

  • "org_invite_link_regenerated"

Organization invite link was regenerated (previous link invalidated).

  • "org_invite_viewed"

An organization invite was viewed.

  • "org_invites_listed"

Organization invites were listed.

  • "org_ip_restriction_created"

Organization IP restriction was created.

  • "org_ip_restriction_deleted"

Organization IP restriction was deleted.

  • "org_ip_restriction_updated"

Organization IP restriction was updated.

  • "org_join_proposal_decided"

Approve or reject decision on a parent-org join proposal.

  • "org_join_request_approved"

Admin approved a join request.

  • "org_join_request_created"

User requested to join an organization.

  • "org_join_request_dismissed"

Admin dismissed a join request.

  • "org_join_request_instant_approved"

Join request was instantly approved.

  • "org_join_requests_bulk_dismissed"

Admin bulk-dismissed join requests.

  • "org_magic_link_second_factor_toggled"

Organization magic link second factor was toggled.

  • "org_member_invites_disabled"

Admin disabled member invites for the organization.

  • "org_member_invites_enabled"

Admin enabled member invites for the organization.

  • "org_members_exported"

Organization members list was exported as CSV.

  • "org_model_default_updated"

An organization or role default model setting was changed by an administrator.

  • "org_parent_join_proposal_created"

Organization parent join proposal was created.

  • "org_parent_search_performed"

Organization parent search was performed.

  • "org_sso_add_initiated"

Organization SSO setup was initiated.

  • "org_sso_connection_activated"

Organization SSO connection was activated.

  • "org_sso_connection_deactivated"

Organization SSO connection was deactivated.

  • "org_sso_connection_deleted"

Organization SSO connection was deleted.

  • "org_sso_group_role_mappings_updated"

Organization SSO group role mappings were updated.

  • "org_sso_provisioning_mode_changed"

Organization SSO provisioning mode was changed.

  • "org_sso_scim_welcome_email_toggled"

Organization SCIM-provisioned welcome email was toggled.

  • "org_sso_seat_tier_assignment_toggled"

Organization SSO seat tier assignment was toggled.

  • "org_sso_seat_tier_mappings_updated"

Organization SSO seat tier mappings were updated.

  • "org_sso_toggled"

Organization SSO was toggled on or off.

  • "org_sync_deleting_synchronized_files_started"

Organization started deleting synchronized files.

  • "org_sync_synchronized_files_deleted"

Organization synchronized files were deleted.

  • "org_taint_added"

A taint was added to an organization.

  • "org_taint_removed"

A taint was removed from an organization.

  • "org_user_deleted"

User was removed from organization.

  • "org_user_invite_accepted"

Organization user invite was accepted.

  • "org_user_invite_deleted"

Organization user invite was deleted.

  • "org_user_invite_re_sent"

Organization user invite was re-sent.

  • "org_user_invite_rejected"

Organization user invite was rejected.

  • "org_user_invite_sent"

Organization user invite was sent.

  • "org_user_left"

User removed themselves from organization.

  • "org_user_shares_retained"

A member left or was removed from the organization while projects, tracks, plugins, or chats they had shared were still shared, and those shares were kept.

  • "org_user_trusted_devices_revoked"

An organization admin revoked a member's trusted devices and signed the member out of all active sessions.

  • "org_user_viewed"

An organization user was viewed.

  • "org_users_listed"

Organization users were listed.

  • "org_work_across_apps_disabled"

The organization's "Let Haijun work across apps" setting was turned off.

  • "org_work_across_apps_enabled"

The organization's "Let Haijun work across apps" setting was turned on.

  • "organization_address_updated"

The organization's billing or shipping address was updated.

  • "organization_icon_deleted"

Organization's custom icon deleted.

  • "organization_icon_updated"

Organization's custom icon uploaded or replaced.

  • "owned_projects_access_restored"

Access to owned projects was restored.

  • "payment_method_updated"

The organization's default payment method was updated.

  • "pending_share_created"

A pending share of a project or track was created for an email address that is not yet an organization member.

  • "pending_share_revoked"

A pending share of a project or track was revoked before the invitee joined the organization.

  • "phone_code_sent"

User requested a phone verification code.

  • "phone_code_verified"

User successfully verified their phone code.

  • "platform_agent_archived"

An agent was archived on the API platform.

  • "platform_agent_created"

An agent was created on the API platform.

  • "platform_agent_deleted"

An agent was deleted from the API platform.

  • "platform_agent_deployment_archived"

An agent deployment was archived on the API platform.

  • "platform_agent_deployment_created"

An agent deployment was created on the API platform.

  • "platform_agent_deployment_deleted"

An agent deployment was deleted from the API platform.

  • "platform_agent_deployment_paused"

An agent deployment was paused on the API platform.

  • "platform_agent_deployment_run_triggered"

An agent deployment was run on demand on the API platform.

  • "platform_agent_deployment_unpaused"

An agent deployment was resumed on the API platform.

  • "platform_agent_deployment_updated"

An agent deployment was updated on the API platform.

  • "platform_agent_session_archived"

An agent session was archived on the API platform.

  • "platform_agent_session_created"

An agent session was created on the API platform.

  • "platform_agent_session_deleted"

An agent session was deleted from the API platform.

  • "platform_agent_session_resource_added"

A resource was attached to an agent session.

  • "platform_agent_session_resource_deleted"

A resource attached to an agent session was removed.

  • "platform_agent_session_resource_updated"

A resource attached to an agent session was updated.

  • "platform_agent_session_thread_archived"

A thread within an agent session was archived.

  • "platform_agent_session_updated"

An agent session was updated on the API platform.

  • "platform_agent_updated"

An agent was updated on the API platform.

  • "platform_api_key_created"

An API key was created.

  • "platform_api_key_updated"

An API key was updated.

  • "platform_app_attest_authentication"

An attested mobile device attempted to exchange an Apple App Attest assertion for Juglow API credentials.

  • "platform_billing_upgraded_to_prepaid"

The organization's API billing was upgraded to the prepaid plan.

  • "platform_clearance_workspace_program_request_cleared"

A workspace's clearance program assignment was removed.

  • "platform_clearance_workspace_program_request_set"

A workspace's clearance program assignment was created or updated.

  • "platform_cost_report_viewed"

The cost report was viewed.

  • "platform_dream_archived"

A Dream (asynchronous memory-consolidation job) was archived.

  • "platform_dream_cancelled"

A Dream (asynchronous memory-consolidation job) was cancelled before it completed.

  • "platform_dream_created"

A Dream (asynchronous memory-consolidation job) was created.

  • "platform_federated_authentication"

A federated workload identity attempted to exchange an OIDC token for Juglow API credentials.

  • "platform_federation_issuer_archived"

An OIDC federation issuer was archived.

  • "platform_federation_issuer_created"

An OIDC federation issuer was created, registering an external identity provider that federation rules can trust for workload authentication.

  • "platform_federation_issuer_updated"

An OIDC federation issuer was updated.

  • "platform_federation_rule_archived"

An OIDC federation rule was archived.

  • "platform_federation_rule_created"

An OIDC federation rule was created, allowing tokens from a federation issuer to authenticate as a service account or user. Rules may additionally match on token claims or a condition expression, which are not included in this event.

  • "platform_federation_rule_updated"

An OIDC federation rule was updated.

  • "platform_federation_rule_workspace_added"

A federation rule was enabled for a workspace.

  • "platform_federation_rule_workspace_removed"

A federation rule was disabled for a workspace.

  • "platform_file_content_downloaded"

Activity logged when file content is downloaded via GET /v1/files/{file_id}/content.

  • "platform_file_deleted"

Activity logged when a file is deleted via DELETE /v1/files/{file_id}.

  • "platform_file_uploaded"

Activity logged when a file is uploaded via POST /v1/files.

  • "platform_memory_created"

An agent memory document was created.

  • "platform_memory_deleted"

An agent memory document was deleted.

  • "platform_memory_store_archived"

An agent memory store was archived. Archived stores reject new memory writes and cannot be attached to new sessions; deletion and redaction remain permitted for privacy scrubbing.

  • "platform_memory_store_created"

An agent memory store was created.

  • "platform_memory_store_deleted"

An agent memory store was deleted. Memory content removal may complete asynchronously for very large stores.

  • "platform_memory_store_updated"

An agent memory store's name, description, or metadata was updated.

  • "platform_memory_updated"

An agent memory document's content or path was updated.

  • "platform_memory_version_redacted"

A historical version of an agent memory document was redacted. Redaction scrubs the stored content of a specific version while preserving the version's existence in the history.

  • "platform_oauth_app_created"

An OAuth app was created.

  • "platform_oauth_app_revoked"

An OAuth app was revoked.

  • "platform_oauth_app_updated"

An OAuth app was updated.

  • "platform_plugin_directory_submission_created"

A plugin directory submission was created on the API platform. A plugin directory submission is a request to list a plugin in the public plugin directory.

  • "platform_plugin_directory_submission_deleted"

A plugin directory submission was deleted on the API platform.

  • "platform_plugin_directory_submission_updated"

A plugin directory submission was updated on the API platform.

  • "platform_service_account_archived"

A service account was archived.

  • "platform_service_account_created"

A service account was created.

  • "platform_service_account_updated"

A service account was updated.

  • "platform_service_account_workspace_member_added"

A service account was added as a member of a workspace.

  • "platform_service_account_workspace_member_removed"

A service account was removed from a workspace.

  • "platform_service_account_workspace_member_updated"

A service account's workspace membership role was updated.

  • "platform_signing_key_created"

Activity logged when a new request-signing key is registered for the org.

  • "platform_signing_key_deleted"

Activity logged when a signing key is permanently deleted.

  • "platform_signing_key_rotated"

Activity logged when an in-memory signing key is rotated.

  • "platform_skill_version_content_downloaded"

The content of a track version was downloaded through the Tracks API.

  • "platform_skill_version_created"

Activity logged when a track version is created via POST /v1/tracks/{skill_id}/versions.

  • "platform_skill_version_deleted"

Activity logged when a track version is deleted via DELETE /v1/tracks/{skill_id}/versions/{version}.

  • "platform_spend_limit_alert_emails_updated"

Spend limit alert email addresses and role targets were updated for an org.

  • "platform_spend_limit_created"

An org-level fixed-dollar spend limit was created.

  • "platform_spend_limit_deleted"

An org-level spend limit was removed.

  • "platform_spend_limit_updated"

An org-level spend limit snooze/ignore state was changed.

  • "platform_usage_report_haijun_code_viewed"

The Haijun Code usage report was viewed.

  • "platform_usage_report_messages_viewed"

The messages usage report was viewed.

  • "platform_workspace_archived"

A workspace was archived.

  • "platform_workspace_created"

A workspace was created.

  • "platform_workspace_inference_data_retention_disabled"

The zero data retention override was disabled for a workspace.

  • "platform_workspace_inference_data_retention_enabled"

The zero data retention override was enabled for a workspace.

  • "platform_workspace_member_added"

A member was added to a workspace.

  • "platform_workspace_member_removed"

A member was removed from a workspace.

  • "platform_workspace_member_updated"

A workspace member was updated.

  • "platform_workspace_member_viewed"

A workspace member was viewed.

  • "platform_workspace_members_listed"

Workspace members were listed.

  • "platform_workspace_rate_limit_deleted"

A workspace rate limit was deleted.

  • "platform_workspace_rate_limit_updated"

A workspace rate limit was created or updated.

  • "platform_workspace_updated"

A workspace was updated.

  • "plugin_installation_preference_updated"

An org admin changed the installation preference for a plugin.

  • "prepaid_auto_recharge_disabled"

Auto-recharge was disabled for API prepaid org.

  • "prepaid_auto_recharge_updated"

Auto-recharge settings were updated for API prepaid org.

  • "prepaid_extra_usage_auto_reload_disabled"

Prepaid usage credit auto-reload was disabled.

  • "prepaid_extra_usage_auto_reload_enabled"

Prepaid usage credit auto-reload was enabled.

  • "prepaid_extra_usage_auto_reload_settings_updated"

Prepaid usage credit auto-reload settings were updated.

  • "primary_owner_transferred"

Primary owner role was transferred to another org member.

  • "rbac_role_assigned"

Admin assigned an RBAC custom role to a principal.

  • "rbac_role_created"

Admin created an RBAC custom role.

  • "rbac_role_deleted"

Admin deleted an RBAC custom role.

  • "rbac_role_grant_updated"

Admin requested a capability grant for an RBAC custom role, or removed it.

Records the admin's change to the role. Whether the grant is currently in effect on the role is reported separately.

  • "rbac_role_permission_added"

Admin added a permission to an RBAC custom role.

Emitted once per requested permission, including permissions the role already had, so a retried request still produces a complete audit record.

  • "rbac_role_permission_removed"

Admin removed a permission from an RBAC custom role.

Emitted once per requested permission, including permissions the role already lacked, so a retried request still produces a complete audit record.

  • "rbac_role_unassigned"

Admin unassigned an RBAC custom role from a principal.

  • "rbac_role_updated"

Admin updated an RBAC custom role.

  • "role_assignment_granted"

Role assignment was granted.

  • "role_assignment_revoked"

Role assignment was revoked.

  • "scim_user_created"

A SCIM user was provisioned.

  • "scim_user_deleted"

A SCIM user was deleted.

  • "scim_user_updated"

A SCIM user was updated.

  • "scoped_api_key_deleted"

A scoped API key was deleted.

  • "scoped_api_key_updated"

A scoped API key was renamed or its activation state changed.

  • "seat_tier_changes_cancelled"

Scheduled seat tier downgrades were cancelled.

  • "seat_tiers_purchased"

Seat tiers were purchased or upgraded on a subscription.

  • "service_created"

Activity logged when an org service is explicitly created.

  • "service_deleted"

Activity logged when an org service is deleted.

  • "service_key_created"

Activity logged when a new org service key is created.

  • "service_key_revoked"

Activity logged when an org service key is revoked.

  • "session_revoked"

User revoked a specific session.

  • "session_share_accessed"

Session share was accessed.

  • "session_share_created"

Session share was created.

  • "session_share_revoked"

Session share was revoked.

  • "slack_workspace_claim_revoked"

A Slack workspace or Enterprise Grid organization was disconnected from the organization for Haijun in Slack.

  • "slack_workspace_claimed"

A Slack workspace or Enterprise Grid organization was connected to the organization for Haijun in Slack.

  • "social_login_succeeded"

A user successfully signed in with a social identity provider (Google, Apple, or Microsoft).

  • "sso_login_failed"

An SSO sign-in attempt failed.

  • "sso_login_initiated"

A user started an SSO sign-in flow.

  • "sso_login_succeeded"

A user successfully signed in with SSO.

  • "sso_second_factor_magic_link"

SSO second factor magic link was used.

  • "step_up_authentication_failed"

An additional identity check failed.

  • "step_up_authentication_succeeded"

The user completed an additional identity check to confirm a sensitive action.

  • "step_up_credential_enrolled"

A user enrolled a passkey for confirming sensitive actions on their account.

  • "subscription_cancellation_scheduled"

Subscription cancellation was scheduled at end of billing period.

  • "subscription_quantity_updated"

Contracted subscription seat quantity was updated.

  • "subscription_renewed"

A cancelled subscription was renewed.

  • "subscription_resumed"

A scheduled subscription cancellation was reversed.

  • "subscription_started"

A new subscription was created (Team or Enterprise).

  • "subscription_upgraded"

Subscription plan was upgraded (e.g. Team to Enterprise).

  • "trusted_device_credential_rotated"

The identity-verification credential of a trusted device was rotated to a new key.

  • "trusted_device_enrolled"

A device was enrolled as a trusted device for the user's account. Trusted devices can be used to confirm the user's identity for sensitive actions.

  • "trusted_device_revoked"

A trusted device was removed from the user's account.

  • "tunnel_archived"

An MCP tunnel was archived.

  • "tunnel_certificate_added"

An inner-TLS CA certificate was added to a tunnel.

  • "tunnel_certificate_revoked"

An inner-TLS CA certificate was revoked from a tunnel.

  • "tunnel_created"

An MCP tunnel was created.

  • "tunnel_token_minted"

An OAuth bearer token for the tunnel management API was minted.

  • "tunnel_token_revealed"

The Cloudflare connector secret for a tunnel was revealed to the caller.

  • "tunnel_token_revoked"

An OAuth bearer token for the tunnel management API was revoked.

  • "tunnel_token_rotated"

The Cloudflare connector secret for a tunnel was rotated.

tunnel_token_id is the id of the newly-issued token. The previous token is invalidated by the rotation and its id is not recorded here.

  • "user_consent_recorded"

User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).

  • "user_consent_revoked"

User revoked a previously granted consent for a specific entity.

  • "user_logged_out"

A user signed out of one or all sessions.

  • "verification_evidence_submitted"

Verification evidence was submitted for an organization's verification.

  • "verification_program_application_created"

An organization applied to a verification program.

  • "workspace_member_spend_limit_created"

A per-member or workspace-default Haijun Code spend limit was created.

  • "workspace_member_spend_limit_deleted"

A per-member or workspace-default Haijun Code spend limit was deleted.

  • "workspace_member_spend_limit_updated"

A per-member Haijun Code spend limit amount was updated.

  • "workspace_spend_limit_alert_emails_updated"

Spend limit alert email recipients were updated for a workspace.

  • "workspace_spend_limit_created"

A workspace-level API spend limit was created.

  • "workspace_spend_limit_deleted"

A workspace-level API spend limit was deleted.

  • limit: optional number

Maximum results (default: 100, max: 5000)

default: 100, minimum: 1, maximum: 5000

  • order: optional "asc" or "desc"

Sort direction by created_at. desc (default) returns newest-first; asc returns oldest-first for incremental sync. Activities become queryable after a short asynchronous ingestion delay. When using asc with after_id for incremental sync, late-arriving rows with timestamps behind the cursor will be skipped; consumers that need at-least-once delivery should periodically re-poll an overlap window via created_at.gte and deduplicate by id. after_id and before_id are relative to this order.

default: desc

  • "asc"
  • "desc"
  • organization_ids: optional array of string

Filter activities by organization IDs (accepts org_... or organization UUID). Enumerate IDs via GET /v1/compliance/organizations.

  • user_ids: optional array of string

Alias for actor_ids[], for consistency with other compliance routes. If both are provided, the lists are merged.

Headers

  • "x-api-key": optional string

Returns

  • data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 511 more

List of activity records. Each element's type field identifies which activity it is and which additional fields are present.

  • AbuseDecisionReceived object

An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.

  • type: optional "abuse_decision_received"

default: abuse_decision_received

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • decision: "blocked" or "unspecified"

The decision applied to the session.

  • "blocked"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • abuse_session_id: optional string or null

The anti-abuse service's opaque session identifier for correlation.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AccountDeleted object

User-initiated self-service account deletion.

  • type: optional "account_deleted"

default: account_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AdminAPIKeyCreated object

An admin API key was created.

  • type: optional "admin_api_key_created"

default: admin_api_key_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • admin_api_key_id: string

Tagged ID of the created admin API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scopes: optional array of string

Scopes granted to the key (empty for legacy non-scoped admin keys)

  • AdminAPIKeyDeleted object

An admin API key was deleted.

  • type: optional "admin_api_key_deleted"

default: admin_api_key_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • admin_api_key_id: string

Tagged ID of the deleted admin API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AdminAPIKeyUpdated object

An admin API key was updated (renamed or activated/deactivated).

  • type: optional "admin_api_key_updated"

default: admin_api_key_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • admin_api_key_id: string

Tagged ID of the updated admin API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "name" or "status" or "unspecified"

The admin API key field that changed

  • "name"
  • "status"
  • "unspecified"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • AdminConnectorRequestResolved object

Admin approved or dismissed pending member requests to enable an MCP connector.

  • type: optional "admin_connector_request_resolved"

default: admin_connector_request_resolved

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • decision: "approved" or "dismissed" or "unspecified"
  • "approved"
  • "dismissed"
  • "unspecified"
  • mcp_server_id: string
  • resolved_count: number
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AdminRequestCreated object

Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).

  • type: optional "admin_request_created"

default: admin_request_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • request_type: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AdminSetupChecklistStepDelegated object

A step of the Haijun Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.

  • type: optional "admin_setup_checklist_step_delegated"

default: admin_setup_checklist_step_delegated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • step: string

The checklist step that was delegated, for example enable_sso or verify_domain.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • delegate_email: optional string or null

Email address the step was delegated to; present only when the delegate is not yet an organization member.

  • delegate_user_id: optional string or null

Tagged ID of the organization member the step was delegated to; absent when the step was delegated to an email address that has not joined the organization.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AdminSetupChecklistStepDelegationCancelled object

The delegation of a Haijun Enterprise admin setup checklist step was cancelled.

  • type: optional "admin_setup_checklist_step_delegation_cancelled"

default: admin_setup_checklist_step_delegation_cancelled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • step: string

The checklist step whose delegation was cancelled.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AgeVerified object

User age was verified.

  • type: optional "age_verified"

default: age_verified

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AnonymousMobileLoginAttempted object

Anonymous mobile login was attempted.

  • type: optional "anonymous_mobile_login_attempted"

default: anonymous_mobile_login_attempted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • APIKeyCreated object

Activity logged when a new API key is created.

  • type: optional "api_key_created"

default: api_key_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • api_key_id: string

The tagged ID of the created API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • restricted_to_organization: optional boolean or null

Whether the key was restricted to the creating organization, rather than granted access across the whole parent organization

  • scopes: optional array of string

The scopes for this API key

  • HaijunArtifactAccessFailed object

An attempt to access an artifact failed.

  • type: optional "haijun_artifact_access_failed"

default: haijun_artifact_access_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_artifact_id: optional string or null

The artifact's identifier, when known.

  • haijun_artifact_version_id: optional string or null

The version of the artifact the user attempted to access, when known.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • reason: optional string or null

The reason access was denied, when recorded.

  • HaijunArtifactCommented object

Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.

  • type: optional "haijun_artifact_commented"

default: haijun_artifact_commented

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

The artifact's identifier.

  • comment_action: "activate_thread" or "create_thread" or "deactivate_thread" or 10 more

The action recorded: for example a new comment thread, a reply to an existing thread, a thread resolved, reopened, or deleted, a thread's Haijun activation granted or revoked, a comment's text rewritten by its author, an existing comment sent to Haijun or withdrawn from Haijun, or a thread resolved by a Haijun session.

  • "activate_thread"
  • "create_thread"
  • "deactivate_thread"
  • "delete_thread"
  • "edit_comment"
  • "move_thread"
  • "reopen"
  • "reply"
  • "resolve"
  • "send_to_haijun"
  • "session_resolve"
  • "unsend_to_haijun"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • actor_outside_organization: optional boolean or null

True when the person who acted belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted commenter or editor access. Absent on older events; treat absence as false.

  • haijun_artifact_comment_id: optional string or null

The comment's identifier. Present when the activity relates to a specific comment, for example a new comment, an author's edit of one, or an existing comment sent to Haijun or withdrawn from Haijun; absent for thread-level actions performed without a comment, such as resolve, reopen, deletion, an activation change, or a resolve by a Haijun session.

  • haijun_artifact_comment_thread_id: optional string or null

The comment thread's identifier.

  • haijun_artifact_version_id: optional string or null

The artifact version the comment activity applied to, when known.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactCommentsViewed object

An artifact's comments were viewed.

  • type: optional "haijun_artifact_comments_viewed"

default: haijun_artifact_comments_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

The artifact's identifier.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_artifact_version_id: optional string or null

The version of the artifact whose comments were served, when known.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactCreated object

An artifact was created.

  • type: optional "haijun_artifact_created"

default: haijun_artifact_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

Tagged ID of the artifact that was created, e.g. "haijun_artifact_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunPublishedArtifactDeleted object

A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Juglow (for example, when it was removed for a policy violation).

  • type: optional "haijun_published_artifact_deleted"

default: haijun_published_artifact_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_published_artifact_id: string

The published artifact's identifier.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactPublished object

A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as haijun_artifact_sharing_updated.

  • type: optional "haijun_artifact_published"

default: haijun_artifact_published

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • artifact_type: string

Artifact type (code, html, react, etc.)

  • haijun_published_artifact_id: string

The published artifact's identifier.

  • title: string

Title of the published artifact

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • actor_outside_organization: optional boolean or null

True when the person who published belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted editor access. Absent on older events; treat absence as false.

  • haijun_artifact_version_id: optional string or null

The version identifier recorded as live by this publish.

  • created_at: optional string

When this activity occurred.

format: date-time

  • description: optional string or null

No longer populated: the gallery-card description supplied at publish time is intentionally omitted from this feed.

  • is_redeploy: optional boolean or null

True when the publish updated an existing artifact; false when the publish created the artifact.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactSharingUpdated object

An artifact's sharing settings were updated.

  • type: optional "haijun_artifact_sharing_updated"

default: haijun_artifact_sharing_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • audience: array of Organization or Users or AnyoneWithLink

The artifact's sharing audience after the change. If empty, the artifact is visible only to its owner.

  • Organization object

Sharing audience: visible to the owning organization.

  • type: optional "organization"

default: organization

  • Users object

Sharing audience: visible to an explicit allowlist of users.

  • type: optional "users"

default: users

  • AnyoneWithLink object

Sharing audience: anyone with the link, including anonymous viewers (an artifact shared to the open internet).

  • type: optional "anyone_with_link"

default: anyone_with_link

  • haijun_artifact_id: string

The artifact's identifier.

  • haijun_artifact_version_id: string

The artifact version's identifier.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • new_mode: optional string or null

The read-axis sharing mode after the change: owner, users, org, or public (anyone on the internet).

  • new_user_count: optional number or null

The number of accounts on the explicit read allowlist after the change. Only meaningful when new_mode is users.

  • new_write_mode: optional string or null

The write-axis sharing mode after the change: owner, users, or org.

  • new_write_user_count: optional number or null

The number of accounts on the explicit write allowlist after the change. Only meaningful when new_write_mode is users.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_mode: optional string or null

The read-axis sharing mode before the change: owner, users, org, or public (anyone on the internet).

  • previous_user_count: optional number or null

The number of accounts on the explicit read allowlist before the change. Only meaningful when previous_mode is users.

  • previous_write_mode: optional string or null

The write-axis sharing mode before the change: owner, users, or org.

  • previous_write_user_count: optional number or null

The number of accounts on the explicit write allowlist before the change. Only meaningful when previous_write_mode is users.

  • HaijunArtifactViewed object

An artifact was viewed.

  • type: optional "haijun_artifact_viewed"

default: haijun_artifact_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

The artifact's identifier.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_artifact_version_id: optional string or null

The version of the artifact the user was served, when known.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AuditLogExportAccessed object

Audit log export file was accessed/downloaded via signed URL.

  • type: optional "audit_log_export_accessed"

default: audit_log_export_accessed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • AuditLogExportStarted object

Audit log export was initiated.

  • type: optional "audit_log_export_started"

default: audit_log_export_started

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • from_date: optional string or null

Start date of the export range

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • to_date: optional string or null

End date of the export range

  • BillingEmailsUpdated object

The organization's billing email recipients were updated.

  • type: optional "billing_emails_updated"

default: billing_emails_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • cc_email_count: optional number or null

Number of 'cc' email recipients.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • primary_email_set: optional boolean or null

Whether a primary billing email is configured.

  • to_email_count: optional number or null

Number of 'to' email recipients.

  • CcrAgentCreated object

A Haijun Code agent was created.

  • type: optional "ccr_agent_created"

default: ccr_agent_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was created, e.g. "cagt_01HX...".

  • default_source_urls_truncated: boolean

Whether default_source_urls was capped and omits some of the granted repositories.

  • display_name: string

The agent's display name at creation time.

  • omitted_source_url_count: number

Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.

  • slug: string

The agent's URL-safe identifier, unique within the organization.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • default_source_urls: optional array of string

The repository URLs the agent works on by default, reduced to scheme, host, and path — credentials and query parameters are never included. Empty with a zero omitted_source_url_count means the agent was created without any default repositories; empty with a non-zero count means repositories were granted but could not be safely rendered. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.

  • guest_policy: optional string or null

Whether the agent responds in Slack channels that include guest users, and in Slack Connect channels shared with other organizations: "allow", "restrict", or "channel" (the agent responds, using only that channel's own content and configuration). In Slack Connect channels "allow" gives at most "channel" access. Omitted when the agent inherits the default policy.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • slack_alias: optional string or null

The Slack trigger word that routes mentions to this agent. An empty value means the agent responds to bare "@Haijun" mentions. Omitted when the agent is not addressable from Slack.

  • CcrAgentDeleted object

A Haijun Code agent was deleted.

  • type: optional "ccr_agent_deleted"

default: ccr_agent_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was deleted, e.g. "cagt_01HX...".

  • cascaded_agent_ids_truncated: boolean

True when more agents were deleted in this cascade than are individually recorded. On a cascade parent event (cascaded_from_agent_id unset), cascaded_agent_ids is capped at 100. On a cascade child event (cascaded_from_agent_id set, emitted when the parent deletion failed after committing child deletions), one event is emitted per deleted child up to 100, and this field indicates additional children were deleted in the same cascade.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • cascaded_agent_ids: optional array of string

Agents assigned to individual Slack channels that were also deleted because agent_id was the agent assigned to their entire Slack workspace. Empty when no such agents were deleted, and always empty on a cascade child event (cascaded_from_agent_id set) — the child's siblings are recorded as their own events, not listed here. Capped at 100 entries; cascaded_agent_ids_truncated is set when the actual count exceeded the cap.

  • cascaded_from_agent_id: optional string or null

When set, the Slack workspace's dedicated agent whose deletion attempt caused this agent to be deleted. The parent's own deletion may have failed after the cascade committed — check for a separate event with agent_id = cascaded_from_agent_id to confirm. Unset on a direct deletion.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyJuglowOidcTokenExchanged object

The Haijun Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.

  • type: optional "ccr_agent_proxy_juglow_oidc_token_exchanged"

default: ccr_agent_proxy_juglow_oidc_token_exchanged

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The Haijun Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.

  • credential_id: string

The credential row the exchange ran for, e.g. "apc_01HX...".

  • profile_id: string

The agent proxy profile the credential belongs to, e.g. "capp_01HX...".

  • role_arn: string

The IAM role the token was exchanged for ("aws" target), e.g. "arn:aws:iam::123456789012:role/example-role". Empty for other targets.

  • role_session_name: string

The role session name the temporary credentials were issued under ("aws" target), matching the session name recorded in the organization's own AWS CloudTrail log. Empty for other targets.

  • service_account: string

The Google Cloud service account the federated token was exchanged into ("gcp" target), e.g. "example@example-project.iam.gserviceaccount.com". Empty when the federated token was used directly, and for other targets.

  • session_id: string

The Haijun Code session whose request triggered the exchange, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).

  • target: string

The credential's configured target, e.g. "aws" or "gcp".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • credentials_expire_at: optional string or null

When the exchanged cloud credentials expire. Unset when the cloud provider did not return a lifetime; such credentials were used for the single triggering request and not cached.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • slack_threads: optional array of object

The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.

  • channel_id: string

The Slack channel ID, e.g. "C0123ABCDE".

  • enterprise_id: string

The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.

  • team_id: string

The Slack workspace (team) ID, e.g. "T0123ABCDE".

  • thread_ts: string

The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.

  • CcrAgentProxyJuglowOidcTokenMinted object

The Haijun Code agent proxy minted a short-lived identity token for an juglow_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.

  • type: optional "ccr_agent_proxy_juglow_oidc_token_minted"

default: ccr_agent_proxy_juglow_oidc_token_minted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The Haijun Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.

  • audience: string

The minted token's audience: the fixed token-exchange audience for the "aws" target, the credential row's Google workload identity pool provider URL for the "gcp" target, or the row's configured audience for the "direct" target.

  • credential_id: string

The credential row the token was minted for, e.g. "apc_01HX...".

  • issuance_path: "broker_report" or "direct" or "proxy_record" or "unspecified"

Which record of the issuance this event is. Unspecified on events published before this field existed.

  • "broker_report"
  • "direct"
  • "proxy_record"
  • "unspecified"
  • mint_jti: string

The identifier of the mint attempt, a bare UUID. One mint through the Haijun Tag mint broker produces two minted events that carry the same value, the broker's own report and the agent proxy's record. A reader counts issuances from the broker's reports by distinct report_id, and several distinct reports that share one mint_jti are the accepted mints of a replayed token. Empty on events for mints that did not travel through the broker.

  • profile_id: string

The agent proxy profile the credential belongs to, e.g. "capp_01HX...".

  • report_id: string

The identity of the mint broker's report itself, a bare UUID. The broker mints it once per report and delivery retries repeat it, so several events carrying one report_id are duplicates of one report and collapse to one issuance. Present on broker_report events only.

  • session_id: string

The Haijun Code session whose request triggered the mint, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).

  • target: string

The credential's configured target, e.g. "aws", "gcp", or "direct".

  • test_mint: string

Set when the token was minted by the gateway verification test that runs while an admin registers a custom-gateway audience: "wrong_subject" for the probe token the gateway must reject, "right_subject" for the control token it must accept. Empty for tokens minted for live sessions.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • slack_threads: optional array of object

The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.

  • channel_id: string

The Slack channel ID, e.g. "C0123ABCDE".

  • enterprise_id: string

The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.

  • team_id: string

The Slack workspace (team) ID, e.g. "T0123ABCDE".

  • thread_ts: string

The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.

  • token_expires_at: optional string or null

When the minted token expires.

format: date-time

  • CcrAgentProxyCredentialCreated object

A Haijun Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Haijun Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.

  • type: optional "ccr_agent_proxy_credential_created"

default: ccr_agent_proxy_credential_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

The credential that was created, e.g. "apc_01HX...".

  • credential_type: string

The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".

  • display_name: string

The credential's display name.

  • host_constraint_truncated: boolean

Whether host_constraint was capped and omits some of the configured host name patterns.

  • profile_id: string

The agent proxy profile the credential belongs to, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • authorization_basis: optional object or null

How the actor was authorized to create this credential. Absent on system-initiated operations and on credentials created via a provisioning link.

  • slack_channel_id: string

The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".

  • slack_enterprise_id: string

The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.

  • slack_team_id: string

The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".

  • via_entitlement_leg: boolean

True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.

  • via_full_manage: boolean

True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.

  • granting_role_ids: optional array of string

The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).

  • via_account_assignment: optional boolean or null

True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.

  • created_at: optional string

When this activity occurred.

format: date-time

  • host_constraint: optional array of string

The host name patterns the credential may be sent to, e.g. "api.example.com" or "*.example.com". At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyCredentialDeleted object

A Haijun Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.

  • type: optional "ccr_agent_proxy_credential_deleted"

default: ccr_agent_proxy_credential_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

The credential that was deleted, e.g. "apc_01HX...".

  • profile_id: string

The agent proxy profile the credential belonged to, e.g. "capp_01HX...". Carried so the deletion can be correlated with the profile's other audit events after the credential row no longer exists.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • authorization_basis: optional object or null

How the actor was authorized to delete this credential.

  • slack_channel_id: string

The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".

  • slack_enterprise_id: string

The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.

  • slack_team_id: string

The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".

  • via_entitlement_leg: boolean

True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.

  • via_full_manage: boolean

True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.

  • granting_role_ids: optional array of string

The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).

  • via_account_assignment: optional boolean or null

True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyCredentialRotated object

A Haijun Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.

  • type: optional "ccr_agent_proxy_credential_rotated"

default: ccr_agent_proxy_credential_rotated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

The replacement credential, e.g. "apc_01HX...".

  • credential_type: string

The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".

  • destinations_repointed: number

The number of agent proxy destinations that referenced the old credential and now reference the replacement.

  • display_name: string

The credential's display name.

  • previous_credential_id: string

The credential that was replaced, e.g. "apc_01HX...".

  • profile_id: string

The agent proxy profile the credential belongs to, e.g. "capp_01HX...".

  • rules_repointed: number

The number of agent proxy rules that referenced the old credential and now reference the replacement.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • authorization_basis: optional object or null

How the actor was authorized to rotate this credential. Absent on automatic rotations initiated by the system rather than by a user.

  • slack_channel_id: string

The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".

  • slack_enterprise_id: string

The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.

  • slack_team_id: string

The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".

  • via_entitlement_leg: boolean

True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.

  • via_full_manage: boolean

True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.

  • granting_role_ids: optional array of string

The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).

  • via_account_assignment: optional boolean or null

True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyCredentialUpdated object

A Haijun Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.

  • type: optional "ccr_agent_proxy_credential_updated"

default: ccr_agent_proxy_credential_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

The credential that was updated, e.g. "apc_01HX...".

  • display_name: string

The credential's display name after the update.

  • host_constraint_truncated: boolean

Whether host_constraint was capped and omits some of the configured host name patterns.

  • profile_id: string

The agent proxy profile the credential belongs to, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • authorization_basis: optional object or null

How the actor was authorized to update this credential.

  • slack_channel_id: string

The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".

  • slack_enterprise_id: string

The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.

  • slack_team_id: string

The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".

  • via_entitlement_leg: boolean

True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.

  • via_full_manage: boolean

True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.

  • granting_role_ids: optional array of string

The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).

  • via_account_assignment: optional boolean or null

True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.

  • created_at: optional string

When this activity occurred.

format: date-time

  • host_constraint: optional array of string

The host name patterns the credential may be sent to after the update, e.g. "api.example.com" or "*.example.com". Populated only when the update changed them. At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updated_fields: optional array of string

Names of the settings included in the update: "display_name", "host_constraint".

  • CcrAgentProxyDestinationDeleted object

An agent proxy destination was deleted.

  • type: optional "ccr_agent_proxy_destination_deleted"

default: ccr_agent_proxy_destination_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_with_profile: boolean

True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyDestination call.

  • destination_id: string

The destination that was deleted, e.g. "apd_01HX...".

  • profile_id: string

The agent proxy profile the destination belonged to, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • cascade_trigger_credential_id: optional string or null

Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the destination's client_tls_credential was the deleted credential). Unset for a direct DeleteAgentProxyDestination call and for the profile-delete cascade (see deleted_with_profile).

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyNetworkEventsListed object

A Haijun Code network activity export was accessed for the given hour.

  • type: optional "ccr_agent_proxy_network_events_listed"

default: ccr_agent_proxy_network_events_listed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • failed: boolean

True when the export request did not complete successfully.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • hour: optional string or null

The UTC hour that was exported.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProfileBound object

A Haijun Code agent proxy profile was bound to a scope, applying its policy to Haijun Code sessions in that scope.

  • type: optional "ccr_agent_proxy_profile_bound"

default: ccr_agent_proxy_profile_bound

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • profile_id: string

The profile that was bound, e.g. "capp_01HX...".

  • scope_id: string

The identifier of the scope the profile was bound to.

  • scope_kind: string

The kind of scope the profile was bound to: "organization", "environment", "account", or "agent".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProfileCreated object

A Haijun Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.

  • type: optional "ccr_agent_proxy_profile_created"

default: ccr_agent_proxy_profile_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • display_name: string

The profile's display name at creation time.

  • profile_id: string

The profile that was created, e.g. "capp_01HX...".

  • slug: string

The profile's URL-safe identifier, unique within the organization.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • github_access: optional array of object

The GitHub repository access the profile grants, one entry per GitHub App installation. Empty when the profile grants no GitHub access.

  • access_mode: string

How repository access is granted: "none" (no access), "list" (exactly the repositories in repos), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.

  • github_installation_id: number

The GitHub App installation the access applies to.

  • repo_count: number

The total number of repositories granted, including any omitted from repos.

  • repos_truncated: boolean

Whether repos was capped and omits some of the granted repositories.

  • ghe_configuration_id: optional number or null

The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.

  • repo_ids: optional array of number

The numeric GitHub repository IDs the profile grants access to, in the same order as repos (and subject to the same 100-entry cap). These IDs are the authoritative identity of the granted repositories — access is enforced against them, not against the display names in repos.

  • repos: optional array of string

Repository names (owner/name) the profile grants access to, populated when access_mode is "list". Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids are the authoritative identity of the granted repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when the granted set is larger.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProfileDeleted object

A Haijun Code agent proxy profile was deleted, removing its policy from everything it was bound to.

  • type: optional "ccr_agent_proxy_profile_deleted"

default: ccr_agent_proxy_profile_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_credential_count: number

Number of credentials deleted together with the profile — deleting a profile also deletes the credentials attached to it. Each deleted credential additionally emits its own ccr_agent_proxy_credential_deleted activity, at most 100 per profile deletion. Best-effort: when deleted_credentials_unknown is true the count could not be determined and 0 here does not mean the profile had no credentials.

  • deleted_credentials_unknown: boolean

Whether the number of credentials deleted with the profile could not be determined. When true, deleted_credential_count is 0 and no per-credential deletion activities were emitted, even though the deletion may have destroyed credentials.

  • deleted_destination_count: number

Number of destinations deleted together with the profile. Each deleted destination additionally emits its own ccr_agent_proxy_destination_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_destinations_unknown is true the count could not be determined and 0 here does not mean the profile had no destinations.

  • deleted_destinations_unknown: boolean

Whether the number of destinations deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.

  • deleted_rule_count: number

Number of rules deleted together with the profile. Each deleted rule additionally emits its own ccr_agent_proxy_rule_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_rules_unknown is true the count could not be determined and 0 here does not mean the profile had no rules.

  • deleted_rules_unknown: boolean

Whether the number of rules deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.

  • profile_id: string

The profile that was deleted, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProfileUnbound object

A Haijun Code agent proxy profile was unbound from a scope, removing its policy from Haijun Code sessions in that scope.

  • type: optional "ccr_agent_proxy_profile_unbound"

default: ccr_agent_proxy_profile_unbound

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • profile_id: string

The profile that was unbound, e.g. "capp_01HX...".

  • scope_id: string

The identifier of the scope the profile was unbound from.

  • scope_kind: string

The kind of scope the profile was unbound from: "organization", "environment", "account", or "agent".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProfileUpdated object

A Haijun Code agent proxy profile's configuration was updated.

  • type: optional "ccr_agent_proxy_profile_updated"

default: ccr_agent_proxy_profile_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • profile_id: string

The profile that was updated, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • github_access_changes: optional array of object

How the profile's GitHub repository access changed, one entry per GitHub App installation whose access changed. Empty when the update did not change GitHub access.

  • access_mode: string

How repository access is granted after the change: "none" (no access), "list" (access is restricted to an explicit repository list — repos_added/repos_removed carry this change's delta and repo_count the post-change total), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.

  • github_installation_id: number

The GitHub App installation the change applies to.

  • repo_count: number

The total number of repositories granted after the change.

  • repos_truncated: boolean

Whether repos_added or repos_removed was capped and omits some of the changed repositories.

  • ghe_configuration_id: optional number or null

The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.

  • previous_access_mode: optional string or null

How repository access was granted before the change. Present only when the access mode changed.

  • repo_ids_added: optional array of number

The numeric GitHub repository IDs added to the granted set, in the same order as repos_added (and subject to the same 100-entry cap). These IDs are the authoritative identity of the added repositories — access is enforced against them, not against the display names in repos_added.

  • repo_ids_removed: optional array of number

The numeric GitHub repository IDs removed from the granted set, in the same order as repos_removed (and subject to the same 100-entry cap). These IDs are the authoritative identity of the removed repositories.

  • repos_added: optional array of string

Repository names (owner/name) added to the granted set. Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids_added are the authoritative identity of the added repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when more were added. Empty when the change involves "all" access, which grants every repository regardless of any explicit list.

  • repos_removed: optional array of string

Repository names (owner/name) removed from the granted set. Same rendering, cap, and "all" handling as repos_added; repo_ids_removed carries the authoritative identity of the removed repositories.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updated_fields: optional array of string

Names of the configuration fields included in the update, e.g. "display_name", "github_installation_permissions".

  • CcrAgentProxyProvisioningCredentialRejected object

An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.

  • type: optional "ccr_agent_proxy_provisioning_credential_rejected"

default: ccr_agent_proxy_provisioning_credential_rejected

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

The credential the member submitted, e.g. "apc_01HX...".

  • link_id: string

The provisioning link's identifier.

  • profile_id: string

The agent proxy profile the credential lived in, e.g. "capp_01HX...".

  • rule_id: string

The disabled rule that was deleted alongside the credential, e.g. "apr_01HX...".

  • submitted_by_user_id: string

The tagged account ID of the user who originally submitted the credential, e.g. "user_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProvisioningLinkEnabled object

An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.

  • type: optional "ccr_agent_proxy_provisioning_link_enabled"

default: ccr_agent_proxy_provisioning_link_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

The credential the member submitted, e.g. "apc_01HX...".

  • link_id: string

The provisioning link's identifier.

  • profile_id: string

The agent proxy profile the credential lives in, e.g. "capp_01HX...".

  • rule_id: string

The rule that was flipped to enforce, e.g. "apr_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProvisioningLinkGenerated object

An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.

  • type: optional "ccr_agent_proxy_provisioning_link_generated"

default: ccr_agent_proxy_provisioning_link_generated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • link_id: string

The provisioning link's identifier. Correlation only; redemption requires an org-member session, so this is not a bearer credential.

  • profile_id: string

The agent proxy profile the submitted credential will be created in, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProvisioningLinkRevoked object

An organization owner revoked an unfilled agent proxy provisioning link.

  • type: optional "ccr_agent_proxy_provisioning_link_revoked"

default: ccr_agent_proxy_provisioning_link_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • link_id: string

The provisioning link's identifier.

  • profile_id: string

The agent proxy profile the link targeted, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyProvisioningLinkSubmitted object

A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.

  • type: optional "ccr_agent_proxy_provisioning_link_submitted"

default: ccr_agent_proxy_provisioning_link_submitted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

The credential that was created, e.g. "apc_01HX...".

  • credential_type: string

The kind of credential, e.g. "bearer" or "basic".

  • link_id: string

The provisioning link's identifier.

  • profile_id: string

The agent proxy profile the credential was created in, e.g. "capp_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • host_constraint: optional array of string

The host name patterns the credential may be sent to.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyRuleCreated object

An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.

  • type: optional "ccr_agent_proxy_rule_created"

default: ccr_agent_proxy_rule_created

  • action: "allow" or "deny" or "require_approval" or "unspecified"

What the rule does with a matching request.

  • "allow"
  • "deny"
  • "require_approval"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • has_condition: boolean

Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.

  • hosts_truncated: boolean

Whether hosts was capped and omits some of the configured host name patterns.

  • injects_credential: boolean

Whether the rule adds a managed credential to the requests it allows.

  • mode: "disabled" or "enforce" or "shadow" or "unspecified"

Whether the rule is enforced, only observed, or switched off.

  • "disabled"
  • "enforce"
  • "shadow"
  • "unspecified"
  • path_pattern_count: number

How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches; 0 when the rule matches every path.

  • ports_truncated: boolean

Whether ports was capped and omits some of the configured ports.

  • priority: number

Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.

  • profile_id: string

The agent proxy profile the rule belongs to, e.g. "capp_01HX...".

  • protocol: "http" or "mysql" or "postgres" or 3 more

The kind of connection the rule applies to.

  • "http"
  • "mysql"
  • "postgres"
  • "ssh"
  • "tcp"
  • "unspecified"
  • rule_id: string

The rule that was created, e.g. "apr_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • hosts: optional array of string

The host name patterns the rule matches, in canonical form (lowercase, internationalized names in their ASCII encoding), e.g. "api.example.com" or "*.example.com". At most 100 entries are included; hosts_truncated indicates when the configured set is larger.

  • injected_credential_id: optional string or null

The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.

  • methods: optional array of string

The HTTP methods the rule matches, e.g. GET. Empty when the rule matches every method.

  • mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more

The kinds of change the rule makes to the requests it allows, each listed once.

  • "inject_credential"
  • "route_to"
  • "set_header"
  • "strip_header"
  • "unspecified"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ports: optional array of number

The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.

  • route_to_destination_id: optional string or null

The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.

  • CcrAgentProxyRuleDeleted object

An agent proxy rule was deleted.

  • type: optional "ccr_agent_proxy_rule_deleted"

default: ccr_agent_proxy_rule_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_with_profile: boolean

True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyRule call or a provisioning-link reject (RejectAgentProxyProvisionedCredential) — the reject case also emits CcrAgentProxyProvisioningCredentialRejected with the same rule_id in the same batch.

  • profile_id: string

The agent proxy profile the rule belonged to, e.g. "capp_01HX...".

  • rule_id: string

The rule that was deleted, e.g. "apr_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • cascade_trigger_credential_id: optional string or null

Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the rule inject_credential-referenced the deleted credential). Unset for a direct DeleteAgentProxyRule call, for the profile-delete cascade (see deleted_with_profile), and for a provisioning-link reject that removed the provisioned rule.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentProxyRuleUpdated object

An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.

  • type: optional "ccr_agent_proxy_rule_updated"

default: ccr_agent_proxy_rule_updated

  • action: "allow" or "deny" or "require_approval" or "unspecified"

What the rule does with a matching request.

  • "allow"
  • "deny"
  • "require_approval"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • has_condition: boolean

Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.

  • hosts_truncated: boolean

Whether hosts was capped and omits some of the configured host name patterns.

  • injects_credential: boolean

Whether the rule adds a managed credential to the requests it allows.

  • mode: "disabled" or "enforce" or "shadow" or "unspecified"

Whether the rule is enforced, only observed, or switched off.

  • "disabled"
  • "enforce"
  • "shadow"
  • "unspecified"
  • path_pattern_count: number

How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches after the update; 0 when the rule matches every path.

  • ports_truncated: boolean

Whether ports was capped and omits some of the configured ports.

  • priority: number

Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.

  • profile_id: string

The agent proxy profile the rule belongs to, e.g. "capp_01HX...".

  • protocol: "http" or "mysql" or "postgres" or 3 more

The kind of connection the rule applies to.

  • "http"
  • "mysql"
  • "postgres"
  • "ssh"
  • "tcp"
  • "unspecified"
  • rule_id: string

The rule that was updated, e.g. "apr_01HX...".

  • version: number

The rule's version after the update; it increases by one on every update.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • hosts: optional array of string

The host name patterns the rule matches after the update, in canonical form (lowercase, internationalized names in their ASCII encoding). At most 100 entries are included; hosts_truncated indicates when the configured set is larger.

  • injected_credential_id: optional string or null

The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.

  • methods: optional array of string

The HTTP methods the rule matches after the update, e.g. GET. Empty when the rule matches every method.

  • mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more

The kinds of change the rule makes to the requests it allows after the update, each listed once.

  • "inject_credential"
  • "route_to"
  • "set_header"
  • "strip_header"
  • "unspecified"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ports: optional array of number

The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.

  • route_to_destination_id: optional string or null

The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.

  • CcrAgentSlackAccessScopeCreated object

A Haijun Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.

  • type: optional "ccr_agent_slack_access_scope_created"

default: ccr_agent_slack_access_scope_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was granted access, e.g. "cagt_01HX...".

  • can_write: boolean

Whether the grant includes permission to post messages in the channel, in addition to reading it.

  • slack_channel_id: string

The Slack channel the agent was granted access to, e.g. "C01ABC...". Empty when the grant covers the entire workspace.

  • slack_team_id: string

The Slack workspace containing the channel, e.g. "T01ABC...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentSlackAccessScopeDeleted object

A Haijun Code agent's access to an additional Slack channel was revoked.

  • type: optional "ccr_agent_slack_access_scope_deleted"

default: ccr_agent_slack_access_scope_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent whose access was revoked, e.g. "cagt_01HX...".

  • slack_channel_id: string

The Slack channel the agent's access was revoked from, e.g. "C01ABC...". Empty when the revoked grant covered the entire workspace.

  • slack_team_id: string

The Slack workspace containing the channel, e.g. "T01ABC...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentSlackBindingCreated object

A Haijun Code agent was assigned to a Slack channel or workspace as its dedicated agent.

  • type: optional "ccr_agent_slack_binding_created"

default: ccr_agent_slack_binding_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent the binding was created for, e.g. "cagt_01HX...".

  • slack_channel_id: string

The Slack channel the agent was assigned to, e.g. "C01ABC...". Empty when the agent was assigned to the entire workspace.

  • slack_team_id: string

The Slack workspace the agent was assigned to, e.g. "T01ABC...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentSlackBindingDeleted object

A Haijun Code agent's assignment to a Slack channel or workspace was removed.

  • type: optional "ccr_agent_slack_binding_deleted"

default: ccr_agent_slack_binding_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent the binding was removed from, e.g. "cagt_01HX...".

  • slack_channel_id: string

The Slack channel the agent was unassigned from, e.g. "C01ABC...". Empty when the assignment covered the entire workspace.

  • slack_team_id: string

The Slack workspace the agent was unassigned from, e.g. "T01ABC...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrAgentUpdated object

A Haijun Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.

  • type: optional "ccr_agent_updated"

default: ccr_agent_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was updated, e.g. "cagt_01HX...".

  • default_source_urls_truncated: boolean

Whether default_source_urls was capped and omits some of the granted repositories.

  • omitted_source_url_count: number

Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • default_source_urls: optional array of string

The agent's default repository URLs after the update, reduced to scheme, host, and path — credentials and query parameters are never included. Populated only when the update changed them — "default_source_urls" appears in updated_fields. Empty while listed in updated_fields AND omitted_source_url_count is 0 means all default repositories were removed. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.

  • guest_policy: optional string or null

The agent's response policy for Slack channels that include guest users and Slack Connect channels shared with other organizations, after the update: "allow", "restrict", "channel" (the agent responds, using only that channel's own content and configuration), or "default" when the update removed the agent-specific policy so the agent inherits the surrounding default. In Slack Connect channels "allow" gives at most "channel" access. Present only when the update changed it.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • slack_alias: optional string or null

The agent's Slack trigger word after the update. Present only when the update changed it. An empty value means the agent responds to bare "@Haijun" mentions.

  • updated_fields: optional array of string

Names of the configuration fields included in the update, e.g. "display_name", "system_prompt_addendum", "guest_policy". Includes "is_virtual" when this update was the first administrator action on an auto-provisioned agent — a durable state change even when no other field was supplied.

  • CcrChannelManagerAdded object

An org owner/admin assigned an organization member to manage the Haijun-in-Slack configuration of one Slack channel.

  • type: optional "ccr_channel_manager_added"

default: ccr_channel_manager_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The channel's Haijun agent (cagt_...) the assignment is recorded against.

  • slack_channel_id: string

The Slack channel the member may now manage, e.g. "C01ABC...".

  • slack_team_id: string

The Slack workspace containing the channel, e.g. "T01ABC...".

  • user_id: string

Tagged ID of the member who was assigned.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrChannelManagerRemoved object

An org owner/admin removed an organization member's assignment to manage the Haijun-in-Slack configuration of one Slack channel.

  • type: optional "ccr_channel_manager_removed"

default: ccr_channel_manager_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The channel's Haijun agent (cagt_...) the assignment was recorded against.

  • slack_channel_id: string

The Slack channel the member managed, e.g. "C01ABC...".

  • slack_team_id: string

The Slack workspace containing the channel, e.g. "T01ABC...".

  • user_id: string

Tagged ID of the member whose assignment was removed.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrRoleChannelAssignmentDeleted object

CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).

  • type: optional "ccr_role_channel_assignment_deleted"

default: ccr_role_channel_assignment_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • previous_channel_count: number

Number of (team, channel) pairs the role was assigned before deletion.

  • role_id: string

Tagged ID of the role whose channel assignment was removed.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrRoleChannelAssignmentUpdated object

CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Haijun-in-Slack channel-manage surface.

  • type: optional "ccr_role_channel_assignment_updated"

default: ccr_role_channel_assignment_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • channel_count: number

Number of channels assigned after the write.

  • previous_channel_count: number

Number of channels assigned before the write.

  • role_id: string

Tagged ID of the role whose channel assignment was written.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • agent_ids: optional array of string

The channel-silo agents (cagt_...) assigned after the write. Capped at 100 entries; channel_count carries the uncapped total.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrSessionCreated object

A Haijun Code session was created. A session is one coding interaction with Haijun.

  • type: optional "ccr_session_created"

default: ccr_session_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The session that was created, e.g. "cse_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • agent_id: optional string or null

The Haijun Code agent attached to the session, e.g. "cagt_01HX...". Omitted when the session was created without an agent.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrSessionDeleted object

A Haijun Code session was deleted.

  • type: optional "ccr_session_deleted"

default: ccr_session_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The session that was deleted, e.g. "cse_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • CcrSessionUpdated object

A Haijun Code session's settings were updated.

  • type: optional "ccr_session_updated"

default: ccr_session_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The session that was updated, e.g. "cse_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updated_fields: optional array of string

Names of the fields included in the update, e.g. "add_tags", "remove_tags".

  • CcrSlackChannelJoined object

Haijun's Slack app joined a public Slack channel at an organization administrator's request.

  • type: optional "ccr_slack_channel_joined"

default: ccr_slack_channel_joined

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • slack_channel_id: string

The Slack channel the app joined, e.g. "C01ABC...".

  • slack_team_id: string

The Slack workspace containing the channel, e.g. "T01ABC...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatSettingsUpdated object

User updated the settings for a conversation.

  • type: optional "haijun_chat_settings_updated"

default: haijun_chat_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string

Tagged ID of the conversation whose settings were updated, e.g. "haijun_chat_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_id: optional string or null

Project ID this chat belongs to, if any

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatSnapshotCreated object

User created/shared a chat snapshot.

  • type: optional "haijun_chat_snapshot_created"

default: haijun_chat_snapshot_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string
  • haijun_chat_snapshot_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatSnapshotDeleted object

User deleted/unshared a chat snapshot.

  • type: optional "haijun_chat_snapshot_deleted"

default: haijun_chat_snapshot_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_snapshot_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_chat_id: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatSnapshotViewed object

User viewed a chat snapshot (authenticated or public/unauthenticated).

  • type: optional "haijun_chat_snapshot_viewed"

default: haijun_chat_snapshot_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_snapshot_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_chat_id: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactDuplicated object

A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.

  • type: optional "haijun_artifact_duplicated"

default: haijun_artifact_duplicated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

Tagged ID of the new artifact created by the duplication. It is owned by the actor and is independent of the source artifact.

  • source_haijun_artifact_id: string

Tagged ID of the artifact that was copied.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • source_haijun_artifact_version_id: optional string or null

The version of the source artifact that was copied into the new artifact.

  • HaijunArtifactExternalSharingPermissionUpdated object

An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.

  • type: optional "haijun_artifact_external_sharing_permission_updated"

default: haijun_artifact_external_sharing_permission_updated

  • action: "allowed" or "revoked" or "unspecified"

Whether the permission was allowed or revoked.

  • "allowed"
  • "revoked"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

Tagged ID of the artifact.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactInviteAccepted object

Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by invitee_email and invitee_user_id.

  • type: optional "haijun_artifact_invite_accepted"

default: haijun_artifact_invite_accepted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

Tagged ID of the artifact the invitation is for.

  • haijun_artifact_invite_id: string

Tagged ID of the invitation that was accepted.

  • invitee_email: string

Email address the invitation was sent to.

  • invitee_user_id: string

Tagged user ID of the account outside the organization that accepted the invitation.

  • role: string

The access level the invitation grants, for example reader.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactInviteCreated object

A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.

  • type: optional "haijun_artifact_invite_created"

default: haijun_artifact_invite_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

Tagged ID of the artifact the invitation is for.

  • haijun_artifact_invite_id: string

Tagged ID of the invitation; the same ID appears on the accepted, role-updated and revoked activities for this invitation, including a later re-invitation of the same address.

  • invitee_email: string

Email address the invitation was sent to.

  • role: string

The access level the invitation grants, for example reader.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactInviteRevoked object

A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.

  • type: optional "haijun_artifact_invite_revoked"

default: haijun_artifact_invite_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

Tagged ID of the artifact the invitation was for.

  • haijun_artifact_invite_id: string

Tagged ID of the invitation that was withdrawn.

  • invitee_email: string

Email address the invitation was sent to.

  • role: string

The access level the invitation granted, for example reader.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • invitee_user_id: optional string or null

Tagged user ID of the account outside the organization that had accepted the invitation; absent when it was withdrawn before anyone accepted.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunArtifactInviteRoleUpdated object

A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.

  • type: optional "haijun_artifact_invite_role_updated"

default: haijun_artifact_invite_role_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_artifact_id: string

Tagged ID of the artifact the invitation is for.

  • haijun_artifact_invite_id: string

Tagged ID of the invitation whose access level was changed.

  • invitee_email: string

Email address the invitation was sent to.

  • role: string

The access level the invitation grants after the change, for example reader.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • invitee_user_id: optional string or null

Tagged user ID of the account outside the organization that had accepted the invitation; absent while the invitation is pending.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_role: optional string or null

The access level the invitation granted before the change, for example commenter.

  • HaijunChatAccessFailed object

A user was denied access to a Haijun.ai chat conversation.

  • type: optional "haijun_chat_access_failed"

default: haijun_chat_access_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string

The chat conversation the user was denied access to, e.g. "haijun_chat_01Ab...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatCreated object

User created a chat.

  • type: optional "haijun_chat_created"

default: haijun_chat_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string

Tagged ID of the created conversation, e.g. "haijun_chat_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_id: optional string or null

Tagged ID of the project the chat was created in, if any, e.g. "haijun_proj_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatDeleted object

A user deleted a Haijun.ai chat conversation.

  • type: optional "haijun_chat_deleted"

default: haijun_chat_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string

The chat conversation that was deleted, e.g. "haijun_chat_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_id: optional string or null

The project the chat belonged to, if any, e.g. "haijun_proj_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatDeletionFailed object

A request to delete a Haijun.ai chat conversation failed.

  • type: optional "haijun_chat_deletion_failed"

default: haijun_chat_deletion_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string

The chat conversation the user attempted to delete, e.g. "haijun_chat_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatSyncSourceCreated object

A sync source was connected for syncing external content into Haijun chats.

  • type: optional "haijun_chat_sync_source_created"

default: haijun_chat_sync_source_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_sync_source_id: string

Tagged ID of the chat-scoped sync source that was created.

  • provider: string

The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • resource_descriptor: optional string or null

A short provider-specific identifier for the external resource that was connected, e.g. owner/repo for GitHub or a file ID for Google Drive.

  • HaijunChatSyncSourceDeleted object

A sync source was disconnected from Haijun chats.

  • type: optional "haijun_chat_sync_source_deleted"

default: haijun_chat_sync_source_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_sync_source_id: string

Tagged ID of the chat-scoped sync source that was deleted.

  • provider: string

The external provider backing the sync source. Always unspecified for deletion events.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatSyncSourceUpdated object

A Haijun chat sync source's configuration was updated.

  • type: optional "haijun_chat_sync_source_updated"

default: haijun_chat_sync_source_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_sync_source_id: string

Tagged ID of the chat-scoped sync source that was updated.

  • provider: string

The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • config_changed: optional boolean or null

Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • resource_descriptor: optional string or null

A short provider-specific identifier for the external resource after the update, e.g. owner/repo for GitHub or a file ID for Google Drive.

  • HaijunChatUpdated object

User updated the chat metadata (e.g name, model).

  • type: optional "haijun_chat_updated"

default: haijun_chat_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string

Tagged ID of the updated conversation, e.g. "haijun_chat_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_id: optional string or null

Tagged ID of the project the chat belongs to, if any, e.g. "haijun_proj_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunChatViewed object

A user viewed a Haijun.ai chat conversation.

  • type: optional "haijun_chat_viewed"

default: haijun_chat_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_chat_id: string

The chat conversation that was viewed, e.g. "haijun_chat_01Ab...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_id: optional string or null

The project the chat belongs to, if any, e.g. "haijun_proj_01Ab...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeCredentialRevoked object

A Haijun Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.

  • type: optional "haijun_code_credential_revoked"

default: haijun_code_credential_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_type: "runner_pool_key" or "runner_token" or "session_token" or "unspecified"

The kind of credential the revoked target identifies, when known. Subject-targeted revocations cascade to every credential delegated from the target regardless of kind; this field describes the target itself, not the full set of credentials the cascade reached. For a revocation submitted as a pasted credential the kind is best-effort and may be inaccurate; the recorded jti and the revocation itself are unaffected.

  • "runner_pool_key"
  • "runner_token"
  • "session_token"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • agent_id: optional string or null

The agent identity whose Haijun Code credentials were revoked, when revocation targeted every session created by an agent identity, e.g. "cagt_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • delegating_jti: optional string or null

The credential identifier whose delegated credentials were revoked (a chain revoke): every credential delegated from this one was revoked, but the credential itself was not. Distinct from jti, which records a revocation of the credential itself and its delegates.

  • jti: optional string or null

The unique identifier of the revoked credential, recorded in its canonical form. Revoking a runner pool key also revokes every runner and session token delegated from it. A revocation submitted as a pasted credential is recorded by that credential's identifier.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • runner_id: optional string or null

The runner whose credentials were revoked, when revocation targeted every credential delegated from the runner, e.g. "ccrunner_01HX...".

  • runner_pool_id: optional string or null

The runner pool whose credentials were revoked, when revocation targeted every credential delegated from the pool, e.g. "ccpool_01HX...".

  • session_id: optional string or null

The session whose credentials were revoked, when revocation targeted every credential delegated from the session, e.g. "cse_01HX...".

  • user_id: optional string or null

The user whose Haijun Code credentials were revoked, when revocation targeted every credential minted for a user. Carries the user's tagged account ID, e.g. "user_01HX..." — the only form the revocation API accepts, so the field joins against other activities' account identifiers and never carries an email.

  • HaijunCodeReviewConfigUpdated object

Haijun Code Review configuration was enabled/disabled for an org.

  • type: optional "haijun_code_review_config_updated"

default: haijun_code_review_config_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enabled: boolean

Whether code review is now enabled

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • environment_id: optional string or null

Environment used for code review

  • model: optional string or null

Model configured for code review

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • per_review_limit_usd: optional string or null

Per-review spend limit in USD

  • previous_enabled: optional boolean or null

Whether code review was enabled before the change. Absent when no configuration existed before this update.

  • previous_environment_id: optional string or null

Environment used for code review before the change. Absent when no configuration existed before this update or no environment was set.

  • previous_model: optional string or null

Model configured for code review before the change. Absent when no configuration existed before this update or no model was set.

  • previous_per_review_limit_usd: optional string or null

Per-review spend limit in USD before the change. Absent when no configuration existed before this update or no limit was set.

  • previous_show_tips: optional boolean or null

Whether tip-style pull-request comments were enabled before the change. Absent when no configuration existed before this update.

  • previous_verification_enabled: optional boolean or null

Whether the verification stage of code review was enabled for the organization before the change. Absent when no configuration existed before this update or no preference was set.

  • show_tips: optional boolean or null

Whether tip-style pull-request comments are now enabled

  • verification_enabled: optional boolean or null

Whether the verification stage of code review is now enabled for the organization. Absent when the organization has not set a preference and the default applies.

  • HaijunCodeReviewRepositoryAdded object

A repository was added to org-level Haijun Code Review configuration.

  • type: optional "haijun_code_review_repository_added"

default: haijun_code_review_repository_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • config_id: string

ID of the repository configuration

  • repo_name: string

Repository name

  • repo_owner: string

Repository owner (GitHub org/user)

  • trigger_mode: string

When code review is triggered

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeReviewRepositoryRemoved object

A repository was removed from org-level Haijun Code Review configuration.

  • type: optional "haijun_code_review_repository_removed"

default: haijun_code_review_repository_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • config_id: string

ID of the deleted repository configuration

  • repo_name: string

Repository name at deletion time

  • repo_owner: string

Repository owner at deletion time

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeReviewRepositoryUpdated object

A Haijun Code Review repository configuration was updated.

  • type: optional "haijun_code_review_repository_updated"

default: haijun_code_review_repository_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • config_id: string

ID of the repository configuration

  • repo_name: string

Repository name

  • repo_owner: string

Repository owner

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • status: optional string or null

Updated status (ACTIVE/INACTIVE)

  • trigger_mode: optional string or null

Updated trigger mode

  • HaijunCodeRunnerDeleted object

A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.

  • type: optional "haijun_code_runner_deleted"

default: haijun_code_runner_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • runner_id: string

The runner that was removed, e.g. "ccrunner_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • runner_pool_id: optional string or null

The pool the runner was removed from, e.g. "ccpool_01HX...".

  • HaijunCodeRunnerPoolCreated object

A self-hosted runner pool for Haijun Code was created.

  • type: optional "haijun_code_runner_pool_created"

default: haijun_code_runner_pool_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • display_name: string

The display name the pool was created with.

  • runner_pool_id: string

The runner pool that was created, e.g. "ccpool_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeRunnerPoolDeleted object

A self-hosted runner pool was deleted.

  • type: optional "haijun_code_runner_pool_deleted"

default: haijun_code_runner_pool_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • runner_pool_id: string

The runner pool that was deleted, e.g. "ccpool_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • display_name: optional string or null

The pool's display name at deletion time.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeRunnerPoolSecretMinted object

A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.

  • type: optional "haijun_code_runner_pool_secret_minted"

default: haijun_code_runner_pool_secret_minted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • jti: string

The minted key's unique identifier (its JWT jti claim), usable to revoke that key later.

  • runner_pool_id: string

The runner pool the key was minted for, e.g. "ccpool_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • expires_at: optional string or null

When the minted key expires.

format: date-time

  • label: optional string or null

The label the key was minted with. The key minted automatically when a pool is created carries the label "Initial key".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeRunnerPoolSessionQueueUpdated object

An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.

  • type: optional "haijun_code_runner_pool_session_queue_updated"

default: haijun_code_runner_pool_session_queue_updated

  • action: "dismissed" or "provisioning_retried" or "requeued" or "unspecified"

What changed about the session's queue state.

  • "dismissed"
  • "provisioning_retried"
  • "requeued"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The session whose queue state changed, e.g. "cse_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • excluded_runner_id: optional string or null

The runner the session was moved off, when action is "requeued", e.g. "ccrunner_01HX...".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • runner_pool_id: optional string or null

The runner pool whose queue the session is in, when known, e.g. "ccpool_01HX...".

  • HaijunCodeRunnerPoolUpdated object

A self-hosted runner pool's settings were updated.

  • type: optional "haijun_code_runner_pool_updated"

default: haijun_code_runner_pool_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • display_name: string

The pool's display name after the update.

  • runner_pool_id: string

The runner pool that was updated, e.g. "ccpool_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_display_name: optional string or null

The pool's display name before the update. Absent when the name was unchanged or the previous value was unavailable.

  • HaijunCodeSecurityCenterConfigUpdated object

Haijun Code Security Center scanning was enabled/disabled for an org.

  • type: optional "haijun_code_security_center_config_updated"

default: haijun_code_security_center_config_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enabled: boolean

Whether Security Center is now enabled

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • environment_id: optional string or null

Environment used for security scanning

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityScanCancelled object

In-flight Haijun Code Security scans were cancelled for a project.

  • type: optional "haijun_code_security_scan_cancelled"

default: haijun_code_security_scan_cancelled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_project_id: string

Tagged ID of the scan project

  • scans_cancelled: number
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityScanCreated object

A Haijun Code Security scan was started.

  • type: optional "haijun_code_security_scan_created"

default: haijun_code_security_scan_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_id: string

Tagged ID of the created scan

  • scan_project_id: string

Tagged ID of the scan project the scan belongs to

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityScanProjectMemberUpdated object

A person's access to a Haijun Code Security scan project was granted, changed, or revoked.

  • type: optional "haijun_code_security_scan_project_member_updated"

default: haijun_code_security_scan_project_member_updated

  • action: "member_added" or "member_removed" or "member_role_changed" or "unspecified"

Whether the member was granted access, had their role changed, or was revoked

  • "member_added"
  • "member_removed"
  • "member_role_changed"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • member_id: string

Tagged ID of the member whose access changed

  • scan_project_id: string

Tagged ID of the scan project

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null

How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.

  • "member"
  • "organization_admin"
  • "organization_share"
  • "owner"
  • "unspecified"
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • role: optional string or null

Role granted to the member (full, view_triage, or view); omitted for revocations

  • HaijunCodeSecurityScanProjectUpdated object

A Haijun Code Security scan project was archived, unarchived, created, or migrated to a new product experience.

  • type: optional "haijun_code_security_scan_project_updated"

default: haijun_code_security_scan_project_updated

  • action: "archived" or "created" or "migrated" or 3 more

The state change applied to the scan project.

  • "archived"
  • "created"
  • "migrated"
  • "resumed"
  • "unarchived"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_project_id: string

Tagged ID of the scan project

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null

How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (the project's creation, or an automated change); events recorded before this field was introduced omit it.

  • "member"
  • "organization_admin"
  • "organization_share"
  • "owner"
  • "unspecified"
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityScanProjectVisibilityUpdated object

A Haijun Code Security scan project was shared with the organization or made private.

  • type: optional "haijun_code_security_scan_project_visibility_updated"

default: haijun_code_security_scan_project_visibility_updated

  • action: "shared" or "unshared" or "unspecified"

Whether the project was shared with the organization or made private

  • "shared"
  • "unshared"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_project_id: string

Tagged ID of the scan project

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_level: optional string or null

Access level granted to organization members (read_only or full); only set when shared

  • access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null

How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.

  • "member"
  • "organization_admin"
  • "organization_share"
  • "owner"
  • "unspecified"
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityScanRunUpdated object

A single Haijun Code Security scan run was archived, unarchived, or resumed after a billing pause.

  • type: optional "haijun_code_security_scan_run_updated"

default: haijun_code_security_scan_run_updated

  • action: "archived" or "created" or "migrated" or 3 more

The state change applied to the scan run

  • "archived"
  • "created"
  • "migrated"
  • "resumed"
  • "unarchived"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_id: string

Tagged ID of the scan the request named — for archive/unarchive any scan in the run, not necessarily its canonical (run_index=0) scan; for resume, the paused scan

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityScanScheduleDeleted object

A recurring scan schedule was deleted for a Haijun Code Security project.

  • type: optional "haijun_code_security_scan_schedule_deleted"

default: haijun_code_security_scan_schedule_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_project_id: string

Tagged ID of the scan project

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityScanScheduleUpdated object

A recurring scan schedule was set or replaced for a Haijun Code Security project.

  • type: optional "haijun_code_security_scan_schedule_updated"

default: haijun_code_security_scan_schedule_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • cadence: string
  • scan_project_id: string

Tagged ID of the scan project

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityVulnerabilityDeleted object

A Haijun Code Security vulnerability finding was permanently deleted.

  • type: optional "haijun_code_security_vulnerability_deleted"

default: haijun_code_security_vulnerability_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_id: string

Tagged ID of the scan the finding belonged to

  • vulnerability_id: number

Numeric ID of the deleted finding, as shown in the product

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityVulnerabilityFixSessionCreated object

A Haijun Code remediation session was created for a Haijun Code Security vulnerability finding.

  • type: optional "haijun_code_security_vulnerability_fix_session_created"

default: haijun_code_security_vulnerability_fix_session_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_id: string

Tagged ID of the scan the finding belongs to

  • session_id: string

ID of the created remediation session

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null

How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved; events recorded before this field was introduced omit it.

  • "member"
  • "organization_admin"
  • "organization_share"
  • "owner"
  • "unspecified"
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityVulnerabilityUpdated object

A Haijun Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.

  • type: optional "haijun_code_security_vulnerability_updated"

default: haijun_code_security_vulnerability_updated

  • action: "dismissed" or "fixed" or "restored" or 2 more

The state change applied to the finding

  • "dismissed"
  • "fixed"
  • "restored"
  • "unfixed"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_id: string

Tagged ID of the scan the finding belongs to

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • dismissal_reason: optional string or null

The categorized dismissal reason (only set when the finding was dismissed)

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCodeSecurityWebhookCreated object

A Haijun Code Security outbound webhook was created.

  • type: optional "haijun_code_security_webhook_created"

default: haijun_code_security_webhook_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • url: string
  • webhook_id: string

Tagged ID of the webhook

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scan_project_id: optional string or null

Tagged ID of the scan project (null for organization-wide webhooks)

  • HaijunCodeSecurityWebhookDeleted object

A Haijun Code Security outbound webhook was deleted.

  • type: optional "haijun_code_security_webhook_deleted"

default: haijun_code_security_webhook_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • webhook_id: string

Tagged ID of the webhook

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scan_project_id: optional string or null

Tagged ID of the scan project (null for organization-wide webhooks)

  • HaijunCodeSecurityWebhookSecretUpdated object

The HMAC signing secret for a Haijun Code Security webhook was rotated.

  • type: optional "haijun_code_security_webhook_secret_updated"

default: haijun_code_security_webhook_secret_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • webhook_id: string

Tagged ID of the webhook

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scan_project_id: optional string or null

Tagged ID of the scan project (null for organization-wide webhooks)

  • HaijunCodeSecurityWebhookUpdated object

A Haijun Code Security outbound webhook was updated.

  • type: optional "haijun_code_security_webhook_updated"

default: haijun_code_security_webhook_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • webhook_id: string

Tagged ID of the webhook

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scan_project_id: optional string or null

Tagged ID of the scan project (null for organization-wide webhooks)

  • HaijunCodeTeamMemoryACLUpdated object

An RBAC group was added to or removed from the Haijun Code team-memory ACL.

  • type: optional "haijun_code_team_memory_acl_updated"

default: haijun_code_team_memory_acl_updated

  • action: "removed" or "set" or "unspecified"

Whether the group was set (added/updated) or removed

  • "removed"
  • "set"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the RBAC group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_level: optional string or null

Access level granted (when action=set)

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_access_level: optional string or null

Access level the group had before this change; absent when the group was not previously in the access list. For removals this is the access level that was removed.

  • HaijunCodeTeamMemoryUpdated object

Haijun Code team memory shared with the organization was updated.

  • type: optional "haijun_code_team_memory_updated"

default: haijun_code_team_memory_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_all: boolean

True when the entire team memory store for this scope was deleted in one request.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • keys_deleted: optional array of string

Withdrawn — never populated. See keys_deleted_count.

  • keys_deleted_count: optional number or null

Number of team memory entries removed.

  • keys_written: optional array of string

Withdrawn — never populated. See keys_written_count.

  • keys_written_count: optional number or null

Number of team memory entries created or updated.

  • new_checksum: optional string or null

Checksum of the team memory after this change.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_checksum: optional string or null

Checksum of the team memory before this change; null when it did not exist.

  • repo: optional string or null

Withdrawn — never populated.

  • version: optional number or null

Version number of the team memory store after this change.

  • HaijunCodeTeamOnboardingGuideUpdated object

A Haijun Code team onboarding guide was created, updated, or deleted.

  • type: optional "haijun_code_team_onboarding_guide_updated"

default: haijun_code_team_onboarding_guide_updated

  • action: "created" or "deleted" or "unspecified" or "updated"

The state change applied to the onboarding guide.

  • "created"
  • "deleted"
  • "unspecified"
  • "updated"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • guide_short_code: string

Short code identifying the onboarding guide — the public URL handle shown in the share link.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • guide_id: optional string or null

Tagged ID of the onboarding guide.

  • guide_name: optional string or null

Withdrawn — never populated.

  • new_checksum: optional string or null

Checksum of the guide content after this change; null when the guide was deleted.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_checksum: optional string or null

Checksum of the guide content before this change; null when the guide did not exist.

  • HaijunCodeUserMarketplacesUpdated object

A user's Haijun Code plugin marketplace selections were updated on Juglow servers.

  • type: optional "haijun_code_user_marketplaces_updated"

default: haijun_code_user_marketplaces_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_all: boolean

True when all of the user's marketplace selections were removed in one request.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • keys_deleted: optional array of string

Withdrawn — never populated. See keys_deleted_count.

  • keys_deleted_count: optional number or null

Number of marketplace selections removed.

  • keys_written: optional array of string

Withdrawn — never populated. See keys_written_count.

  • keys_written_count: optional number or null

Number of marketplace selections added or whose source changed.

  • new_value: optional string or null

Withdrawn — never populated.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional string or null

Withdrawn — never populated.

  • HaijunCodeUserMemoryUpdated object

A user's synced private Haijun Code memory was updated or deleted on Juglow servers.

  • type: optional "haijun_code_user_memory_updated"

default: haijun_code_user_memory_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_all: boolean

True when the user's entire synced memory for this scope was deleted in one request.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • keys_deleted: optional array of string

Withdrawn — never populated. See keys_deleted_count.

  • keys_deleted_count: optional number or null

Number of memory file paths removed.

  • keys_written: optional array of string

Withdrawn — never populated. See keys_written_count.

  • keys_written_count: optional number or null

Number of memory file paths created or updated.

  • new_checksum: optional string or null

Checksum of the user's synced memory after this change.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_checksum: optional string or null

Checksum of the user's synced memory before this change; null when the store did not exist.

  • repo: optional string or null

Withdrawn — never populated.

  • HaijunCodeUserPluginsUpdated object

A user's Haijun Code plugin selections — which plugins are installed and enabled — were updated on Juglow servers.

  • type: optional "haijun_code_user_plugins_updated"

default: haijun_code_user_plugins_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_all: boolean

True when all of the user's plugin selections were removed in one request.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • keys_deleted: optional array of string

Withdrawn — never populated. See keys_deleted_count.

  • keys_deleted_count: optional number or null

Number of plugin selections removed.

  • keys_written: optional array of string

Withdrawn — never populated. See keys_written_count.

  • keys_written_count: optional number or null

Number of plugin selections added or whose enabled state changed.

  • new_value: optional string or null

The targeted plugin's new enabled state, when a single plugin's state changed.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional string or null

The targeted plugin's previous enabled state, when a single plugin's state changed; null when the plugin did not previously exist or multiple plugins changed.

  • HaijunCodeUserSettingsUpdated object

A user's synced Haijun Code settings were updated or deleted on Juglow servers.

  • type: optional "haijun_code_user_settings_updated"

default: haijun_code_user_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deleted_all: boolean

True when the user's entire synced settings store was deleted in one request.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • keys_deleted: optional array of string

Withdrawn — never populated. See keys_deleted_count.

  • keys_deleted_count: optional number or null

Number of settings entries removed.

  • keys_written: optional array of string

Withdrawn — never populated. See keys_written_count.

  • keys_written_count: optional number or null

Number of settings entries created or updated.

  • new_checksum: optional string or null

Checksum of the user's synced settings after this change.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_checksum: optional string or null

Checksum of the user's synced settings before this change; null when the store did not exist.

  • HaijunEnterpriseUpgradeCreditUpdated object

An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.

  • type: optional "haijun_enterprise_upgrade_credit_updated"

default: haijun_enterprise_upgrade_credit_updated

  • action: "cancelled" or "resumed" or "unspecified"

Whether the credit was cancelled or turned back on

  • "cancelled"
  • "resumed"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunFileAccessFailed object

A user was denied access to a file in Haijun.ai.

  • type: optional "haijun_file_access_failed"

default: haijun_file_access_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_file_id: string

The file the user was denied access to, e.g. "haijun_file_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_artifact_id: optional string or null

The artifact the file was accessed through, if any, e.g. "haijun_artifact_01HX...".

  • haijun_project_id: optional string or null

The project the file was accessed through, if any, e.g. "haijun_proj_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • filename: optional string or null

Deprecated

Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.

  • HaijunFileExported object

A file was exported from Haijun to an external storage destination.

  • type: optional "haijun_file_exported"

default: haijun_file_exported

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • export_destination: "google_drive" or "unspecified"

The external destination the file was exported to.

  • "google_drive"
  • "unspecified"
  • filename: string

Name of the exported file.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_chat_id: optional string or null

The chat conversation the file was exported from, if the export originated in a chat, e.g. "haijun_chat_01HX...".

  • haijun_file_id: optional string or null

The exported file, e.g. "haijun_file_01HX...", if the file has a stored file record; files that exist only inside a session have no file ID.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunFileViewed object

A user viewed a file in Haijun.ai.

  • type: optional "haijun_file_viewed"

default: haijun_file_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_file_id: string

The file that was viewed, e.g. "haijun_file_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_artifact_id: optional string or null

The artifact the file was accessed through, if any, e.g. "haijun_artifact_01HX...".

  • haijun_project_id: optional string or null

The project the file was accessed through, if any, e.g. "haijun_proj_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • filename: optional string or null

Deprecated

Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.

  • HaijunPluginArchiveAccessed object

A version archive of a member-owned plugin, containing that member's own files, was downloaded.

  • type: optional "haijun_plugin_archive_accessed"

default: haijun_plugin_archive_accessed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • marketplace_id: string

The member's personal marketplace the plugin belongs to.

  • owner_user_id: string

The member who owns the plugin.

  • plugin_id: string

The plugin whose archive was downloaded.

  • plugin_version_id: string

The version whose archive was downloaded.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectSyncSourceCreated object

A sync source was connected to a Haijun project's knowledge base.

  • type: optional "haijun_project_sync_source_created"

default: haijun_project_sync_source_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project the sync source was connected to.

  • haijun_project_sync_source_id: string

Tagged ID of the per-project sync source that was created.

  • provider: string

The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • resource_descriptor: optional string or null

A short provider-specific identifier for the external resource that was connected, e.g. owner/repo for GitHub or a file ID for Google Drive.

  • HaijunProjectSyncSourceDeleted object

A sync source was disconnected from a Haijun project's knowledge base.

  • type: optional "haijun_project_sync_source_deleted"

default: haijun_project_sync_source_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project the sync source was disconnected from.

  • haijun_project_sync_source_id: string

Tagged ID of the per-project sync source that was deleted.

  • provider: string

The external provider backing the sync source. Always unspecified for deletion events.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectSyncSourceUpdated object

A Haijun project sync source's configuration was updated.

  • type: optional "haijun_project_sync_source_updated"

default: haijun_project_sync_source_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project the sync source belongs to.

  • haijun_project_sync_source_id: string

Tagged ID of the per-project sync source that was updated.

  • provider: string

The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • config_changed: optional boolean or null

Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • resource_descriptor: optional string or null

A short provider-specific identifier for the external resource after the update, e.g. owner/repo for GitHub or a file ID for Google Drive.

  • HaijunUserSeatTierUpdated object

An organization member's seat tier was changed. A null previous_seat_tier means the member previously had no seat assigned; a null current_seat_tier means the seat was removed.

  • type: optional "haijun_user_seat_tier_updated"

default: haijun_user_seat_tier_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_email: string

Email address of the member at the time of the change.

  • user_id: string

Tagged ID of the member whose seat tier changed.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_seat_tier: optional string or null

The member's seat tier after this change, or null if the seat was removed.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_seat_tier: optional string or null

The member's seat tier before this change, or null if no seat was assigned.

  • CliPluginExecPolicyUpdated object

Admin set or cleared the per-op permission ceiling for a plugin CLI.

  • type: optional "cli_plugin_exec_policy_updated"

default: cli_plugin_exec_policy_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • cli_name: string

CLI name as declared by the plugin manifest

  • marketplace_id: string

Marketplace ID owning the plugin

  • op_name: string

Op name (or '*' for the per-CLI default)

  • plugin_id: string

Plugin ID resolved from the URL

  • plugin_name: string

Plugin name within its marketplace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • max_permission: optional string or null

New max_permission value ('allow' | 'ask' | 'blocked'), or null when cleared

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_max_permission: optional string or null

Max permission the op had before this change ('allow' | 'ask' | 'blocked'), or null when no policy existed for the op

  • HaijunCommandCreated object

Command was created.

  • type: optional "haijun_command_created"

default: haijun_command_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • command_id: optional string or null
  • command_name: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCommandDeleted object

Command was deleted.

  • type: optional "haijun_command_deleted"

default: haijun_command_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • command_id: optional string or null
  • command_name: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunCommandReplaced object

Command was replaced.

  • type: optional "haijun_command_replaced"

default: haijun_command_replaced

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • command_id: optional string or null
  • command_name: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ComplianceAPIAccessed object

Logging event auto-generated for each compliance API request.

  • type: optional "compliance_api_accessed"

default: compliance_api_accessed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • request_id: string

Identifier of the request, as returned in the response's request-id header

  • request_method: "DELETE" or "GET" or "POST" or 2 more

HTTP method of the request

  • "DELETE"
  • "GET"
  • "POST"
  • "PUT"
  • "unspecified"
  • status_code: number

HTTP status code

  • url: string

Full URL that was requested, including any query string

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • request_body: optional string or null

Serialized JSON request body

  • CoworkSessionUpdated object

A Cowork session was updated.

  • type: optional "cowork_session_updated"

default: cowork_session_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • cowork_session_id: string

Tagged ID of the updated session, e.g. "sess_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_id: optional string or null

Tagged ID of the project the session was moved to, if any, e.g. "haijun_proj_01HX...". Absent when the session was removed from its project.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DesignProjectArtifactPublished object

A Haijun Design project's content was published as a haijun.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.

  • type: optional "design_project_artifact_published"

default: design_project_artifact_published

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project whose content was published, e.g. "design_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • is_public: optional boolean or null

True when the published artifact is publicly viewable after this call (anyone with the link). False when it is not — by default, a newly published artifact is visible only to the person who published it.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type: "project", "template", or "design_system".

  • DesignProjectCreated object

A Haijun Design project was created.

  • type: optional "design_project_created"

default: design_project_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • creation_method: string

How the project was created: "direct", "duplicate", "remix", or "template_from_project".

  • design_project_id: string

The Design project that was created, e.g. "design_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project type: "project", "template", or "design_system".

  • source_project_id: optional string or null

The source project this was created from, when created via duplicate, remix, or template-from-project. Unset for direct creation.

  • DesignProjectDeleted object

A Haijun Design project was deleted.

  • type: optional "design_project_deleted"

default: design_project_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project that was deleted, e.g. "design_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DesignProjectMemberAdded object

A member was granted access to a Haijun Design project.

  • type: optional "design_project_member_added"

default: design_project_member_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project the member was added to, e.g. "design_proj_01HX...".

  • principal_id: string

The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".

  • principal_type: string

The kind of member that was added: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).

  • role: string

The role the member was granted: "viewer", "commenter", or "editor". Access-group ("compartment") members are always view-only.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type: "project", "template", or "design_system".

  • DesignProjectMemberRemoved object

A member's access to a Haijun Design project was revoked.

  • type: optional "design_project_member_removed"

default: design_project_member_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project the member was removed from, e.g. "design_proj_01HX...".

  • principal_id: string

The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".

  • principal_type: string

The kind of member that was removed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type: "project", "template", or "design_system".

  • DesignProjectMemberRoleUpdated object

A Haijun Design project member's role was changed.

  • type: optional "design_project_member_role_updated"

default: design_project_member_role_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project the member belongs to, e.g. "design_proj_01HX...".

  • principal_id: string

The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".

  • principal_type: string

The kind of member whose role was changed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).

  • role: string

The member's role after the change: "viewer", "commenter", or "editor".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_role: optional string or null

The member's role before the change.

  • project_type: optional string or null

The project's type: "project", "template", or "design_system".

  • DesignProjectPublished object

A Haijun Design template or design system was published, making it discoverable by everyone in its organization.

  • type: optional "design_project_published"

default: design_project_published

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project that was published, e.g. "design_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type: "template" or "design_system".

  • DesignProjectSharingUpdated object

A Haijun Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).

  • type: optional "design_project_sharing_updated"

default: design_project_sharing_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project whose sharing settings changed, e.g. "design_proj_01HX...".

  • new_link_permission: string

What people opening the project through its link may do after the change: "view", "comment", or "edit".

  • new_scope: string

Who the project link is set to work for after the change: "invited" (only the owner and individually invited members) or "org" (anyone in the project's organization, where the organization's own sharing settings allow org-wide visibility). This records the project's stored setting as changed by the actor; organization-level settings can further restrict who the link actually admits, and changes to those settings are not project events. Projects created before link sharing was restricted may also report a legacy "public" value.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_link_permission: optional string or null

What people opening the project through its link could do before the change.

  • previous_scope: optional string or null

Who the project link was set to work for before the change — the stored setting, with the same organization-level caveat as new_scope. May include the legacy "public" value.

  • project_type: optional string or null

The project's type: "project", "template", or "design_system".

  • DesignProjectUnpublished object

A Haijun Design template or design system was unpublished, removing it from its organization's shared gallery.

  • type: optional "design_project_unpublished"

default: design_project_unpublished

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project that was unpublished, e.g. "design_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type: "template" or "design_system".

  • DesignProjectUpdated object

A Haijun Design project's metadata was updated.

  • type: optional "design_project_updated"

default: design_project_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project that was updated, e.g. "design_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type after the update: "project", "template", or "design_system". Present only when the update changed it.

  • updated_fields: optional array of string

Names of the fields changed by this update, e.g. "name", "description", "project_type", "design_systems".

  • DesignProjectVersionRestored object

A Haijun Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.

  • type: optional "design_project_version_restored"

default: design_project_version_restored

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project that was restored, e.g. "design_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type: "project", "template", or "design_system".

  • DesignProjectViewed object

A Haijun Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.

This activity type is retired: project content reads are no longer recorded. Events of this type may still appear in feeds for reads that occurred while it was active.

  • type: optional "design_project_viewed"

default: design_project_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • design_project_id: string

The Design project whose content was read, e.g. "design_proj_01HX...".

  • surface: string

Which read surface recorded this open: "project" (the project was opened), "project_data" (the project's full contents were read or made readable — either a direct data read, which also includes the project's conversations when the reader's access extends to them, or a render-token request, which exposes the project's files for the token's lifetime; the two share this value and are not distinguished), "file" (one of the project's files was read), "version" (a saved version of the project's files, including their contents, was read — version-history browsing that lists names without contents is not recorded), or "export" (an authenticated export of the project's contents was requested).

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_via: optional string or null

How the viewer was authorized to open the project: "owner" (the project's owner), "member_grant" (an individually invited member), "org_link" (org-wide link sharing), "trusted_service" (an authorized agent), or "design_system_reference" (an indirect read of a design system through a project that uses it).

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • project_type: optional string or null

The project's type: "project", "template", or "design_system".

  • DesktopExtensionAllowlisted object

A desktop extension was added to an org's allowlist.

  • type: optional "desktop_extension_allowlisted"

default: desktop_extension_allowlisted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • extension_id: string

Allowlisted DXT extension ID

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DesktopExtensionBlocklisted object

A desktop extension was added to the global blocklist.

  • type: optional "desktop_extension_blocklisted"

default: desktop_extension_blocklisted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • extension_id: string

Blocklisted DXT extension ID

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DesktopExtensionDeleted object

A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.

  • type: optional "desktop_extension_deleted"

default: desktop_extension_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • extension_id: string

DXT extension ID

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • version: optional string or null

Specific version deleted (null if all versions)

  • DesktopExtensionRemovedFromAllowlist object

A desktop extension was removed from an org's allowlist.

  • type: optional "desktop_extension_removed_from_allowlist"

default: desktop_extension_removed_from_allowlist

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • extension_id: string

DXT extension ID removed from allowlist

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DesktopExtensionUnblocked object

A desktop extension was removed from the global blocklist.

  • type: optional "desktop_extension_unblocked"

default: desktop_extension_unblocked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • extension_id: string

Unblocked DXT extension ID

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DesktopExtensionUploaded object

A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.

  • type: optional "desktop_extension_uploaded"

default: desktop_extension_uploaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • extension_id: string

DXT extension ID

  • version: string

Version string from the manifest

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DesktopExtensionVersionUploaded object

A new version of an existing org-owned desktop extension was uploaded.

  • type: optional "desktop_extension_version_uploaded"

default: desktop_extension_version_uploaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • extension_id: string

DXT extension ID

  • version: string

Version string from the manifest

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • InferenceHooksConfigDeleted object

Inference hooks configuration was removed for the organization.

  • type: optional "inference_hooks_config_deleted"

default: inference_hooks_config_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • InferenceHooksConfigUpdated object

Inference hooks configuration was created or updated for the organization.

  • type: optional "inference_hooks_config_updated"

default: inference_hooks_config_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enabled: boolean

Whether Inference hooks enforcement is enabled after this change.

  • enforcement_mode: string

Whether Inference hooks inspects both prompts and responses (prompt_and_response) or prompts only (prompt_only).

  • fail_mode: string

Whether requests are allowed (fail_open) or blocked (fail_closed) when the Inference hooks endpoint cannot be reached.

  • final_verdict_timeout_ms: number

Milliseconds inference waits for the Inference hooks verdict on the response.

  • prompt_verdict_timeout_ms: number

Milliseconds inference waits for the Inference hooks verdict on the prompt.

  • webhook_url: string

The endpoint that inspected prompts and responses are sent to.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • deny_message: optional string or null

Administrator-written text shown to users at the end of the error message when a request is blocked by the organization's Inference hooks policy, as configured after this change. Null when the built-in default message is in effect; an empty string when the administrator configured an empty message, in which case no text is appended.

  • deny_message_enabled: optional boolean or null

Whether the organization has the appended deny message turned on, as configured after this change. When on, the administrator-written message (or the built-in default, when none is configured) is appended to the error users see when a request is blocked by the organization's Inference hooks policy; no text is appended when the administrator-written message is empty, or when this is off.

  • extra_header_names: optional array of string or null

Names of the custom HTTP headers attached to every Inference hooks request after this change, or null when this update did not change headers. Header values are write-only and are not recorded.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • reset_circuit_breaker: optional boolean or null

Whether this update carried an explicit request to clear the circuit breaker. A tripped breaker otherwise survives configuration updates; it also clears whenever an update enables enforcement.

  • rollout_percentage: optional number or null

Percentage of requests (0-100) inspected by Inference hooks after this change, or null when this update did not change it. 0 disables inspection; 100 inspects every request.

  • shadow_mode: optional boolean or null

Whether the organization's Inference hooks run in shadow mode after this change, or null when this update did not change it. In shadow mode, prompts are still sent to the organization's endpoint and verdicts are recorded, but requests are never blocked.

  • InferenceHooksSigningSecretGenerated object

A request signing secret was generated for the organization's Inference hooks configuration.

  • type: optional "inference_hooks_signing_secret_generated"

default: inference_hooks_signing_secret_generated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • rotated: boolean

Whether this generation replaced an existing signing secret (true) or created the organization's first one (false). Replacing a secret invalidates the previous one immediately.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • DomainClaimInitiated object

Domain capture claim initiated over personal accounts on verified domains.

  • type: optional "domain_claim_initiated"

default: domain_claim_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • EndUserInviteRequested object

Non-admin member submitted an invite request for a new org member.

  • type: optional "end_user_invite_requested"

default: end_user_invite_requested

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • invitee_email: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ExtraUsageBillingEnabled object

Usage credit billing was enabled for an organization.

  • type: optional "extra_usage_billing_enabled"

default: extra_usage_billing_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ExtraUsageCreditGranted object

A promotional usage credit grant was claimed.

  • type: optional "extra_usage_credit_granted"

default: extra_usage_credit_granted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ExtraUsageSpendLimitCreated object

Usage credit spend limit was created.

  • type: optional "extra_usage_spend_limit_created"

default: extra_usage_spend_limit_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • amount: optional number or null

The monthly credit limit amount in minor units (e.g. cents).

  • created_at: optional string

When this activity occurred.

format: date-time

  • is_enabled: optional boolean or null

Whether the spend limit is enabled.

  • limit_type: optional string or null

The type of spend limit created (e.g. organization, seat_tier, member, service, group).

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

Tagged ID of the spend limit.

  • user_id: optional string or null

Deprecated

Deprecated. Tagged ID of the admin who performed the action — not the target member. Use spend_limit_id to look up the target member.

  • ExtraUsageSpendLimitDeleted object

Usage credit spend limit was deleted.

  • type: optional "extra_usage_spend_limit_deleted"

default: extra_usage_spend_limit_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

Tagged ID of the spend limit.

  • user_id: optional string or null

Deprecated

Deprecated. Tagged ID of the admin who performed the action — not the target member. Use spend_limit_id to look up the target member.

  • ExtraUsageSpendLimitIncreaseRequestApproved object

A usage credit spend limit increase request was approved.

  • type: optional "extra_usage_spend_limit_increase_request_approved"

default: extra_usage_spend_limit_increase_request_approved

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • amount: optional number or null

The approved spend limit amount in minor units (e.g. cents).

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • requester_user_id: optional string or null

Tagged ID of the member who requested the increase, e.g. "user_01HX...".

  • spend_limit_id: optional string or null

Tagged ID of the member's spend limit that the approval created or updated.

  • spend_limit_increase_request_id: optional string or null

Tagged ID of the spend limit increase request that was approved.

  • ExtraUsageSpendLimitIncreaseRequestDenied object

A usage credit spend limit increase request was denied.

  • type: optional "extra_usage_spend_limit_increase_request_denied"

default: extra_usage_spend_limit_increase_request_denied

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • requester_user_id: optional string or null

Tagged ID of the member who requested the increase, e.g. "user_01HX...".

  • spend_limit_increase_request_id: optional string or null

Tagged ID of the spend limit increase request that was denied.

  • ExtraUsageSpendLimitUpdated object

Usage credit spend limit was updated.

  • type: optional "extra_usage_spend_limit_updated"

default: extra_usage_spend_limit_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • amount: optional number or null

The new monthly credit limit amount in minor units (e.g. cents).

  • created_at: optional string

When this activity occurred.

format: date-time

  • is_enabled: optional boolean or null

Whether the spend limit is enabled.

  • limit_type: optional string or null

The type of spend limit updated (e.g. organization, seat_tier, member, service, group).

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

Tagged ID of the spend limit.

  • user_id: optional string or null

Deprecated

Deprecated. Tagged ID of the admin who performed the action — not the target member. Use spend_limit_id to look up the target member.

  • HaijunFileDeleted object

A file was deleted.

  • type: optional "haijun_file_deleted"

default: haijun_file_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_file_id: string

Tagged ID of the file that was deleted, e.g. "haijun_file_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the deleted file, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunFileUploaded object

A file was uploaded.

  • type: optional "haijun_file_uploaded"

default: haijun_file_uploaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_file_id: string

Tagged ID of the file that was uploaded, e.g. "haijun_file_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_chat_id: optional string or null

Chat ID if known at upload time (null for the upload-then-attach flow). To find which chats a file was later attached to, use GET /v1/compliance/apps/chats/files/{haijun_file_id}.

  • haijun_project_id: optional string or null

Project ID if file was uploaded to a project

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the uploaded file, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GheConfigurationCreated object

Admin created a GHE configuration.

  • type: optional "ghe_configuration_created"

default: ghe_configuration_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • ghe_configuration_id: string

ID of the GHE configuration

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • display_name: optional string or null

Display name given to the configuration

  • hostname: optional string or null

Hostname of the GitHub Enterprise instance

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • port: optional number or null

Custom port, if not the HTTPS default

  • GheConfigurationDeleted object

Admin deleted a GHE configuration.

  • type: optional "ghe_configuration_deleted"

default: ghe_configuration_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • ghe_configuration_id: string

ID of the GHE configuration

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • display_name: optional string or null

Display name the configuration had when deleted

  • hostname: optional string or null

Hostname of the GitHub Enterprise instance

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • port: optional number or null

Custom port, if not the HTTPS default

  • GheConfigurationUpdated object

Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.

  • type: optional "ghe_configuration_updated"

default: ghe_configuration_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • ghe_configuration_id: string

ID of the GHE configuration

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • custom_ca_certificate_updated: optional boolean or null

Whether the custom CA certificate was replaced in this update

  • display_name: optional string or null

New display name, when it changed

  • github_app_client_id: optional string or null

New GitHub App client ID, when it changed

  • github_app_client_secret_updated: optional boolean or null

Whether the GitHub App client secret was replaced in this update

  • github_app_id: optional number or null

New GitHub App ID, when it changed

  • github_app_private_key_updated: optional boolean or null

Whether the GitHub App private key was replaced in this update

  • hostname: optional string or null

Hostname of the GitHub Enterprise instance (immutable; included for context)

  • is_active: optional boolean or null

New active state, when it changed

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • port: optional number or null

New port, when it changed

  • previous_display_name: optional string or null

Display name before the change, when it changed

  • previous_github_app_client_id: optional string or null

GitHub App client ID before the change, when it changed

  • previous_github_app_id: optional number or null

GitHub App ID before the change, when it changed

  • previous_is_active: optional boolean or null

Active state before the change, when it changed

  • previous_port: optional number or null

Port before the change, when it changed

  • read_replica_hostnames_updated: optional boolean or null

Whether the read replica hostnames were replaced in this update

  • webhook_secret_updated: optional boolean or null

Whether the webhook secret was replaced in this update

  • GheUserConnected object

User connected to a GHE instance.

  • type: optional "ghe_user_connected"

default: ghe_user_connected

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • ghe_configuration_id: optional string or null

ID of the GHE configuration

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GheUserDisconnected object

User disconnected from a GHE instance.

  • type: optional "ghe_user_disconnected"

default: ghe_user_disconnected

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • ghe_configuration_id: optional string or null

ID of the GHE configuration

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GheWebhookSignatureInvalid object

Webhook signature validation failed.

  • type: optional "ghe_webhook_signature_invalid"

default: ghe_webhook_signature_invalid

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • ghe_configuration_id: string

ID of the GHE configuration

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunGitHubIntegrationCreated object

A GitHub integration was enabled for the organization.

  • type: optional "haijun_github_integration_created"

default: haijun_github_integration_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • integration_id: string

Tagged ID of the GitHub integration, e.g. "haijun_sync_source_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • enabled: optional boolean or null

Whether the integration is enabled after this change.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_name: optional string or null

Name of the GitHub organization the integration is connected to, when known.

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_enabled: optional boolean or null

Whether the integration was enabled before this change; null when the integration had never been configured.

  • repository_name: optional string or null

Name of the GitHub repository the integration is connected to, when known.

  • HaijunGitHubIntegrationDeleted object

A GitHub integration was disabled for the organization.

  • type: optional "haijun_github_integration_deleted"

default: haijun_github_integration_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • integration_id: string

Tagged ID of the GitHub integration, e.g. "haijun_sync_source_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • enabled: optional boolean or null

Whether the integration is enabled after this change.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_name: optional string or null

Name of the GitHub organization the integration was connected to, when known.

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_enabled: optional boolean or null

Whether the integration was enabled before this change; null when the integration had never been configured.

  • repository_name: optional string or null

Name of the GitHub repository the integration was connected to, when known.

  • HaijunGitHubIntegrationUpdated object

A GitHub integration's configuration was updated.

  • type: optional "haijun_github_integration_updated"

default: haijun_github_integration_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • integration_id: string

Tagged ID of the GitHub integration, e.g. "haijun_sync_source_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_name: optional string or null

Name of the GitHub organization the integration is connected to, when known.

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • repository_name: optional string or null

Name of the GitHub repository the integration is connected to, when known.

  • GitHubAppInstallationLinked object

An installation of the Haijun GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Haijun Code features act on that GitHub account's repositories.

  • type: optional "github_app_installation_linked"

default: github_app_installation_linked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • github_installation_id: number

Numeric GitHub ID of the installation that was linked

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • github_account_login: optional string or null

Login of the GitHub organization or user account the App is installed on

  • github_account_type: optional string or null

Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GitHubAppInstallationUnlinked object

An installation of the Haijun GitHub App was unlinked from the organization, so the organization's Haijun Code features can no longer act on that GitHub account's repositories through it.

  • type: optional "github_app_installation_unlinked"

default: github_app_installation_unlinked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • github_installation_id: number

Numeric GitHub ID of the installation that was unlinked

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • github_account_login: optional string or null

Login of the GitHub organization or user account the App is installed on

  • github_account_type: optional string or null

Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GitHubTokenImport object

A user attempted to import a personal GitHub access token for use with Haijun Code. The result field indicates the outcome of the import (imported, rejected, or failed).

  • type: optional "github_token_import"

default: github_token_import

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • result: "failed_internal" or "imported" or "rejected_feature_disabled" or 5 more

The outcome of the import.

  • "failed_internal"
  • "imported"
  • "rejected_feature_disabled"
  • "rejected_invalid_credential"
  • "rejected_missing_repo_scope"
  • "rejected_tenant_not_ready"
  • "rejected_zdr_policy"
  • "unspecified"
  • source: string

How the token was imported.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • github_username: optional string or null

The GitHub username the imported token authenticates as, when known.

  • granted_scopes: optional string or null

The scopes granted to the imported token, when available.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • token_fingerprint_sha256: optional string or null

Org-scoped SHA-256 of the submitted token: sha256(org_uuid || 0x00 || token), lowercase-hex-encoded, where org_uuid is the organization's UUID as a dashed lowercase string, 0x00 is a single zero byte, and token is the submitted value's raw bytes. Per-org correlation only — the same token in two orgs produces distinct fingerprints. Set only when the submitted value carries a known GitHub PAT prefix (a high-entropy token format); unset for all other submissions, including rejected non-PAT input.

  • GitlabConfigurationCreated object

An organization admin created a self-managed GitLab configuration for syncing plugin marketplaces.

  • type: optional "gitlab_configuration_created"

default: gitlab_configuration_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • gitlab_configuration_id: string

ID of the GitLab configuration

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • display_name: optional string or null

Display name given to the configuration

  • hostname: optional string or null

Hostname of the GitLab instance

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • port: optional number or null

Custom port, if not the HTTPS default

  • GitlabConfigurationDeleted object

An organization admin deleted a self-managed GitLab configuration.

  • type: optional "gitlab_configuration_deleted"

default: gitlab_configuration_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • gitlab_configuration_id: string

ID of the GitLab configuration

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • display_name: optional string or null

Display name the configuration had when deleted

  • hostname: optional string or null

Hostname of the GitLab instance

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • port: optional number or null

Custom port, if not the HTTPS default

  • GitlabConfigurationUpdated object

An organization admin updated a self-managed GitLab configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.

  • type: optional "gitlab_configuration_updated"

default: gitlab_configuration_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • gitlab_configuration_id: string

ID of the GitLab configuration

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_token_updated: optional boolean or null

Whether the access token was replaced in this update

  • created_at: optional string

When this activity occurred.

format: date-time

  • custom_ca_certificate_updated: optional boolean or null

Whether the custom CA certificate was replaced in this update

  • display_name: optional string or null

New display name, when it changed

  • hostname: optional string or null

Hostname of the GitLab instance (immutable; included for context)

  • is_active: optional boolean or null

New active state, when it changed

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • port: optional number or null

New port, when it changed

  • previous_display_name: optional string or null

Display name before the change, when it changed

  • previous_is_active: optional boolean or null

Active state before the change, when it changed

  • previous_port: optional number or null

Port before the change, when it changed

  • HaijunGdriveIntegrationCreated object

A Google Drive integration was enabled for the organization.

  • type: optional "haijun_gdrive_integration_created"

default: haijun_gdrive_integration_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • integration_id: string

Tagged ID of the Google Drive integration, e.g. "haijun_sync_source_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • folder_id: optional string or null

Identifier of the Google Drive folder the integration is connected to, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunGdriveIntegrationDeleted object

A Google Drive integration was disabled for the organization.

  • type: optional "haijun_gdrive_integration_deleted"

default: haijun_gdrive_integration_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • integration_id: string

Tagged ID of the Google Drive integration, e.g. "haijun_sync_source_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • folder_id: optional string or null

Identifier of the Google Drive folder the integration was connected to, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunGdriveIntegrationUpdated object

A Google Drive integration's configuration was updated.

  • type: optional "haijun_gdrive_integration_updated"

default: haijun_gdrive_integration_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • integration_id: string

Tagged ID of the Google Drive integration, e.g. "haijun_sync_source_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • folder_id: optional string or null

Identifier of the Google Drive folder the integration is connected to, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupCreated object

A group was created (RBAC admin or SCIM provisioning).

  • type: optional "group_created"

default: group_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the created group

  • group_name: string

Name of the created group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupDeleted object

A group was deleted (RBAC admin or SCIM provisioning).

  • type: optional "group_deleted"

default: group_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the deleted group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupListViewed object

Admin viewed the list of RBAC groups.

  • type: optional "group_list_viewed"

default: group_list_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupMemberAdded object

One or more members were added to a group.

  • type: optional "group_member_added"

default: group_member_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • member_ids: optional array of string

Tagged IDs of the members added: user IDs, or service account IDs (svac_...) when a service account was added

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupMemberAdditionFailed object

A request to add members to a group failed. Some of the requested members may have been added before the failure.

  • type: optional "group_member_addition_failed"

default: group_member_addition_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • member_ids: optional array of string

Tagged IDs of the members the request attempted to add

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupMemberListViewed object

Admin viewed the members of an RBAC group.

  • type: optional "group_member_list_viewed"

default: group_member_list_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupMemberRemovalFailed object

A request to remove members from a group failed. Some of the requested members may have been removed before the failure.

  • type: optional "group_member_removal_failed"

default: group_member_removal_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • member_ids: optional array of string

Tagged IDs of the members the request attempted to remove. These are always recorded as user IDs, since whether a member was a service account is only established once its removal succeeds

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupMemberRemoved object

One or more members were removed from a group.

  • type: optional "group_member_removed"

default: group_member_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • member_ids: optional array of string

Tagged IDs of the members removed: user IDs, or service account IDs (svac_...) when a service account was removed. A requested member that was not in the group is listed as a user ID

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupProjectSharesRevoked object

An RBAC group's project shares in one organization were revoked in bulk.

  • type: optional "group_project_shares_revoked"

default: group_project_shares_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group whose project shares were revoked.

  • revoked_count: number

Number of distinct projects whose share with this group was revoked.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_ids: optional array of string

Tagged IDs of the projects whose share with this group was revoked.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupSkillSharesRevoked object

An RBAC group's track shares in one organization were revoked in bulk.

  • type: optional "group_skill_shares_revoked"

default: group_skill_shares_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group whose track shares were revoked.

  • revoked_count: number

Number of distinct tracks and plugins whose share with this group was revoked: the combined size of skill_ids and plugin_ids.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_ids: optional array of string

Tagged IDs of the plugins whose share with this group was revoked.

  • skill_ids: optional array of string

Tagged IDs of the tracks whose share with this group was revoked.

  • GroupUpdated object

A group was updated (RBAC admin or SCIM provisioning).

  • type: optional "group_updated"

default: group_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the updated group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupViewed object

A group was viewed.

  • type: optional "group_viewed"

default: group_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the viewed group

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • GroupVisibilityUpdated object

An RBAC group's visibility policy was updated.

  • type: optional "group_visibility_updated"

default: group_visibility_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • group_id: string

Tagged ID of the group whose visibility policy was updated.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • policies: optional array of object

The group's visibility policy after this update.

  • audience: "everyone" or "members" or "none" or "unspecified"

The audience granted this visibility facet.

  • "everyone"
  • "members"
  • "none"
  • "unspecified"
  • visibility_type: "discover" or "share_with" or "unspecified" or "view_members"

The visibility facet this entry grants.

  • "discover"
  • "share_with"
  • "unspecified"
  • "view_members"
  • previous_policies: optional array of object

The group's visibility policy before this update.

  • audience: "everyone" or "members" or "none" or "unspecified"

The audience granted this visibility facet.

  • "everyone"
  • "members"
  • "none"
  • "unspecified"
  • visibility_type: "discover" or "share_with" or "unspecified" or "view_members"

The visibility facet this entry grants.

  • "discover"
  • "share_with"
  • "unspecified"
  • "view_members"
  • InferenceHooksCircuitBreakerTripped object

The organization's Inference hooks circuit breaker tripped automatically: calls to the organization's Inference hooks endpoint crossed a failure threshold, and inspection was suspended to protect live traffic. While tripped, requests are handled according to the organization's failure handling setting — allowed through uninspected (fail open) or rejected (fail closed) — and no per-request Inference hooks activities are recorded. The tripped state persists until an administrator re-enables Inference hooks inspection (or explicitly resets the circuit breaker).

  • type: optional "inference_hooks_circuit_breaker_tripped"

default: inference_hooks_circuit_breaker_tripped

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • fail_mode: string

The failure handling in effect when the breaker tripped: "fail_open" (requests proceed uninspected) or "fail_closed" (requests are rejected).

  • trigger_reason: string

The kind of failure that crossed the threshold. Currently always "webhook_error": repeated failures of calls to the organization's Inference hooks endpoint.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • surface: optional string or null

The product surface of the request whose failure tripped the breaker, e.g. "haijun-ai" or "haijun-code".

  • InferenceHooksRequestDenied object

Inference hooks inspection denied a request. The request was blocked and no model response was produced.

  • type: optional "inference_hooks_request_denied"

default: inference_hooks_request_denied

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • conversation_id: optional string or null

The conversation the denied request belonged to, when available. The identifier format depends on surface.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • reference_id: optional string or null

The Inference hooks endpoint's own identifier for this scan, when it returned one — lets this denial be matched to the corresponding record in the inspection provider's console.

  • request_id: optional string or null

Juglow's identifier for the denied request — the same value sent to the Inference hooks endpoint as request_id.

  • surface: optional string or null

The product surface the request came from, e.g. "haijun-ai" or "haijun-code".

  • InferenceHooksRequestFailedOpen object

A request proceeded without Inference hooks inspection because a verdict could not be obtained and the organization's Inference hooks configuration is set to fail open.

  • type: optional "inference_hooks_request_failed_open"

default: inference_hooks_request_failed_open

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • reason: "endpoint_error" or "endpoint_timeout" or "internal_error" or "unspecified"

Why Inference hooks inspection did not return a verdict.

  • "endpoint_error"
  • "endpoint_timeout"
  • "internal_error"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • conversation_id: optional string or null

The conversation the request belonged to, when available. The identifier format depends on surface.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • request_id: optional string or null

Juglow's identifier for the request that proceeded uninspected. When a call to the Inference hooks endpoint was made for this request, it carried this value as request_id.

  • surface: optional string or null

The product surface the request came from, e.g. "haijun-ai" or "haijun-code".

  • IntegrationUserConnected object

User connected to an integration.

  • type: optional "integration_user_connected"

default: integration_user_connected

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • integration_type: optional string or null

The kind of integration the user connected, e.g. "github", "gdrive", "slack", or "mcp" for a remote MCP server.

  • mcp_server_id: optional string or null

ID of the connected remote MCP server, when the integration is a remote MCP server.

  • mcp_server_name: optional string or null

Display name of the connected remote MCP server, when the integration is a remote MCP server.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • token_vault_connect_mode: optional string or null

How a token vault credential sign-in was completed: "authorization_server" for a sign-in at an administrator-provided authorization server, or "mcp_server" for a sign-in at a tool server the organization has not registered as a connector.

  • IntegrationUserDisconnected object

User disconnected from an integration.

  • type: optional "integration_user_disconnected"

default: integration_user_disconnected

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • integration_type: optional string or null

The kind of integration the user disconnected, e.g. "github", "gdrive", "slack", or "mcp" for a remote MCP server.

  • mcp_server_id: optional string or null

ID of the disconnected remote MCP server, when the integration is a remote MCP server.

  • mcp_server_name: optional string or null

Display name of the disconnected remote MCP server, when the integration is a remote MCP server.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • InvoiceCollectionMethodUpdated object

Invoice collection method was changed.

  • type: optional "invoice_collection_method_updated"

default: invoice_collection_method_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • new_collection_method: optional string or null

New collection method (e.g. charge_automatically, send_invoice).

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • UserLoggedOut object

A user signed out of one or all sessions.

  • type: optional "user_logged_out"

default: user_logged_out

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • LtiLaunchInitiated object

LTI launch was initiated.

  • type: optional "lti_launch_initiated"

default: lti_launch_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • LtiLaunchSuccess object

LTI launch completed successfully.

  • type: optional "lti_launch_success"

default: lti_launch_success

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • LtiPlatformCreated object

Juglow staff created an LTI platform integration on behalf of an org.

  • type: optional "lti_platform_created"

default: lti_platform_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • lti_platform_id: string

UUID of the LTI platform

  • lti_platform_issuer: string

Platform issuer URL

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • LtiPlatformUpdated object

Juglow staff updated an LTI platform integration on behalf of an org.

  • type: optional "lti_platform_updated"

default: lti_platform_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • lti_platform_id: string

UUID of the LTI platform

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • lti_platform_issuer: optional string or null

Platform issuer URL

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • MagicLinkLoginFailed object

A magic link sign-in attempt failed.

  • type: optional "magic_link_login_failed"

default: magic_link_login_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • MagicLinkLoginInitiated object

A user requested a magic link sign-in email.

  • type: optional "magic_link_login_initiated"

default: magic_link_login_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • MagicLinkLoginSucceeded object

A user successfully signed in with a magic link email.

  • type: optional "magic_link_login_succeeded"

default: magic_link_login_succeeded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • auth_method: optional "magic_link" or "unspecified" or null

The method the user used to authenticate. May be absent on activities recorded before this field was introduced.

  • "magic_link"
  • "unspecified"
  • created_at: optional string

When this activity occurred.

format: date-time

  • mfa_method: optional "not_used" or "unspecified" or null

The second authentication factor performed during this login, if any. null when the second-factor status is not recorded on this event — for example, when authentication was delegated to an external identity provider and any second factor is not visible to Juglow, or when this event is one step of a multistep login whose MFA is reported on another activity. May be absent on activities recorded before this field was introduced.

  • "not_used"
  • "unspecified"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ManagedOrganizationSetupCompleted object

Managed (AWS Marketplace) organization setup was completed.

  • type: optional "managed_organization_setup_completed"

default: managed_organization_setup_completed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • MarketplaceCreated object

Admin created an organization marketplace.

  • type: optional "marketplace_created"

default: marketplace_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • marketplace_id: string

Tagged ID of the marketplace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • default_installation_preference: optional string or null

Default installation preference the marketplace was created with, applied to its plugins that have no preference of their own (required, auto_install, available or not_available); absent when none was set

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • MarketplaceDeleted object

Admin deleted an organization marketplace.

  • type: optional "marketplace_deleted"

default: marketplace_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • marketplace_id: string

Tagged ID of the marketplace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • MarketplaceUpdated object

Admin updated an organization marketplace.

  • type: optional "marketplace_updated"

default: marketplace_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • marketplace_id: string

Tagged ID of the marketplace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The setting changes applied in this update; empty for an update that changed no recorded setting (such as a sync)

  • type: "default_installation_preference" or "unspecified"

The marketplace setting that changed

  • "default_installation_preference"
  • "unspecified"
  • current_value: string

Setting value immediately after this change; empty when the setting is no longer set

  • previous_value: string

Setting value immediately before this change; empty when the setting was not set

  • MarketplaceWebhookDeleted object

Admin removed the GitHub push webhook for a marketplace.

  • type: optional "marketplace_webhook_deleted"

default: marketplace_webhook_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • marketplace_id: string

Tagged ID of the marketplace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • MarketplaceWebhookProvisioned object

Admin provisioned a GitHub push webhook for a marketplace.

  • type: optional "marketplace_webhook_provisioned"

default: marketplace_webhook_provisioned

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • marketplace_id: string

Tagged ID of the marketplace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • github_webhook_id: optional number or null

GitHub-assigned webhook ID returned by the hooks API

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • McpDirectoryServerPublished object

The organization published its approved MCP directory listing.

  • type: optional "mcp_directory_server_published"

default: mcp_directory_server_published

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • mcp_directory_server_id: string

Tagged ID of the MCP directory listing

  • mcp_directory_server_name: string

Display name of the MCP directory listing

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • McpServerCreated object

An MCP server was added to the organization.

  • type: optional "mcp_server_created"

default: mcp_server_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • mcp_server_id: string

Tagged ID of the MCP server

  • mcp_server_name: string

Display name of the MCP server

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • McpServerDeleted object

An MCP server was removed from the organization.

  • type: optional "mcp_server_deleted"

default: mcp_server_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • mcp_server_id: string

Tagged ID of the MCP server

  • mcp_server_name: string

Display name of the MCP server

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • McpServerManagedAuthTokenExchanged object

A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.

  • type: optional "mcp_server_managed_auth_token_exchanged"

default: mcp_server_managed_auth_token_exchanged

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • managed_auth_mode: string

The managed-authorization mode used for the exchange ("haijun" or "sso").

  • mcp_server_id: string

The MCP server the exchange was attempted for, e.g. "mcpsrv_01Ab...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • assertion_jti: optional string or null

The JWT ID of the identity assertion presented to the authorization server, when one was minted, for cross-reference with the identity provider's own logs.

  • authorization_server_issuer: optional string or null

The issuer identifier of the authorization server the exchange was attempted against.

  • correlation_id: optional string or null

An opaque identifier customers can quote when contacting Juglow support about this exchange.

  • created_at: optional string

When this activity occurred.

format: date-time

  • error_subtype: optional string or null

A more specific classification of the failure, when available. For authorization-server rejections this is the OAuth error code the server returned (for example "invalid_grant"); for identity-provider rejections this is the error code the identity provider returned; for refused identity assertions this is a short reason code such as "not_org_member" (the user's membership in the organization could not be confirmed). Values may be added over time; treat an unrecognized value as a generic failure.

  • error_type: optional string or null

A short classification of why the exchange failed, when outcome is "failure". Values include "authorization_server_rejected", "authorization_server_unavailable", "identity_provider_rejected", "sso_session_invalid", "sso_connection_unsupported", "connector_scope_not_granted" and "identity_assertion_refused". The last two are refusals made before a token exchange was attempted: "connector_scope_not_granted" means the organization's role configuration grants no scopes on this connector; "identity_assertion_refused" means no identity assertion could be issued for this user and server (for example, the user's membership in the organization could not be confirmed), and is reported when access the user already had could not be renewed and, depending on the reason, when first connecting; error_subtype names the reason. Values may be added over time; treat an unrecognized value as a generic failure.

  • mcp_server_name: optional string or null

The MCP server's display name at the time of the exchange, when available.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • outcome: optional string or null

Whether the token exchange succeeded ("success") or was rejected ("failure").

  • McpServerManagedAuthUpdated object

An MCP server's enterprise managed authorization settings were set, changed, or cleared, including when they were supplied while the server was being added or edited. Fields without a "previous_" prefix describe the settings after the change and are null when the server has no managed authorization settings afterwards; "previous_" fields describe the settings before the change and are null when the server had none before (always the case for a newly added server).

  • type: optional "mcp_server_managed_auth_updated"

default: mcp_server_managed_auth_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • mcp_server_id: string

Tagged ID of the MCP server

  • mcp_server_name: string

Display name of the MCP server

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • allowed_scopes: optional string or null

The OAuth scopes managed authorization may request for the server after the change, as a space-delimited list. Null when no scope restriction is configured (or the server has no managed authorization settings); an empty string when the restriction permits no scopes.

  • built_in_roles_included: optional boolean or null

Whether, after the change, managed authorization extends to members who hold one of the organization's built-in roles (such as User, Admin, or Owner) rather than a custom role, in addition to members whose custom role grants it. This describes whom managed authorization reaches and is reported on every change, independent of how built-in role access is configured.

  • created_at: optional string

When this activity occurred.

format: date-time

  • individual_auth_enabled: optional boolean or null

Whether members may authorize the server individually, through their own sign-in and consent, after the change.

  • managed_auth_enabled: optional boolean or null

Whether managed authorization is enabled for the server after the change, so that members whose role permits it are authorized through the organization's identity provider.

  • managed_auth_mode: optional string or null

The managed-authorization mode after the change ("haijun" or "sso"): how the identity assertion presented on members' behalf is issued. Recorded whenever managed authorization settings exist, whether or not managed authorization is enabled; null when the server has no managed authorization settings after the change.

  • mcp_server_url: optional string or null

Origin (scheme, host and port, the default port omitted) of the MCP server at the time of the change; the path is never included. Null when not available.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_allowed_scopes: optional string or null

The OAuth scope restriction before the change, as a space-delimited list; null when no scope restriction was configured.

  • previous_built_in_roles_included: optional boolean or null

Whether managed authorization extended to members holding one of the organization's built-in roles before the change.

  • previous_individual_auth_enabled: optional boolean or null

Whether members could authorize the server individually before the change.

  • previous_managed_auth_enabled: optional boolean or null

Whether managed authorization was enabled for the server before the change.

  • McpServerUpdated object

An MCP server's configuration was updated.

  • type: optional "mcp_server_updated"

default: mcp_server_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • mcp_server_id: string

Tagged ID of the MCP server

  • mcp_server_name: string

Display name of the MCP server

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • McpToolPolicyUpdated object

The permission restriction for an MCP tool was set or cleared.

  • type: optional "mcp_tool_policy_updated"

default: mcp_tool_policy_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • mcp_server_id: string

Tagged ID of the MCP server

  • mcp_server_name: string

Display name of the MCP server

  • tool_name: string

Tool name (or '*' for the MCP-server-wide default)

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • max_permission: optional string or null

New max_permission value ('allow' | 'ask' | 'blocked'), or null when cleared

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgAnalyticsAPICapabilityUpdated object

Organization analytics_api capability was enabled or disabled.

  • type: optional "org_analytics_api_capability_updated"

default: org_analytics_api_capability_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Whether the analytics API capability is enabled immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Whether the analytics API capability was enabled immediately before this change

  • OrgBulkDeleteInitiated object

Organization bulk deletion was initiated.

  • type: optional "org_bulk_delete_initiated"

default: org_bulk_delete_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCapabilityGrantAdded object

A capability grant was added to a workspace or role.

  • type: optional "org_capability_grant_added"

default: org_capability_grant_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • grant_type: string

The type of capability grant that was added.

  • principal_id: string

Tagged ID of the principal the grant was added to.

  • principal_type: "rbac_role" or "unspecified" or "workspace"

The kind of principal the grant was added to.

  • "rbac_role"
  • "unspecified"
  • "workspace"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCapabilityGrantRemoved object

A capability grant was removed from a workspace or role.

  • type: optional "org_capability_grant_removed"

default: org_capability_grant_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • grant_type: string

The type of capability grant that was removed.

  • principal_id: string

Tagged ID of the principal the grant was removed from.

  • principal_type: "rbac_role" or "unspecified" or "workspace"

The kind of principal the grant was removed from.

  • "rbac_role"
  • "unspecified"
  • "workspace"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgHaijunCodeDataSharingDisabled object

Organization Haijun Code data sharing was disabled.

  • type: optional "org_haijun_code_data_sharing_disabled"

default: org_haijun_code_data_sharing_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgHaijunCodeDataSharingEnabled object

Organization Haijun Code data sharing was enabled.

  • type: optional "org_haijun_code_data_sharing_enabled"

default: org_haijun_code_data_sharing_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgHaijunCodeDesktopDisabled object

Organization Haijun Code Desktop was disabled.

  • type: optional "org_haijun_code_desktop_disabled"

default: org_haijun_code_desktop_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgHaijunCodeDesktopEnabled object

Organization Haijun Code Desktop was enabled.

  • type: optional "org_haijun_code_desktop_enabled"

default: org_haijun_code_desktop_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgHaijunCodeZeroDataRetentionDisabled object

A primary owner disabled zero data retention for Haijun Code, so Haijun Code content is retained according to the organization's data retention settings.

  • type: optional "org_haijun_code_zero_data_retention_disabled"

default: org_haijun_code_zero_data_retention_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgComplianceAPISettingsUpdated object

Organization compliance API settings were updated.

  • type: optional "org_compliance_api_settings_updated"

default: org_compliance_api_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • compliance_api_enabled: optional boolean or null

Whether the compliance API is enabled for the organization after this change.

  • compliance_api_logging_enabled: optional boolean or null

Whether compliance activity logging is enabled for the organization after this change.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgConnectorDomainGuardUpdated object

Enterprise admin changed whether connectors are restricted to verified domains.

  • type: optional "org_connector_domain_guard_updated"

default: org_connector_domain_guard_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enforced: boolean
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkActWithoutAskingModeDisabled object

The "Act without asking" mode in Cowork was disabled for the organization, so members can no longer let Haijun act without asking for approval.

  • type: optional "org_cowork_act_without_asking_mode_disabled"

default: org_cowork_act_without_asking_mode_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkActWithoutAskingModeEnabled object

The "Act without asking" mode in Cowork was enabled for the organization, allowing members to let Haijun act without asking for approval.

  • type: optional "org_cowork_act_without_asking_mode_enabled"

default: org_cowork_act_without_asking_mode_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkAgentDisabled object

Organization Cowork Agent was disabled.

  • type: optional "org_cowork_agent_disabled"

default: org_cowork_agent_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgCoworkAgentEnabled object

Organization Cowork Agent was enabled.

  • type: optional "org_cowork_agent_enabled"

default: org_cowork_agent_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgCoworkAutoModeDisabled object

The "Auto" permission mode in Cowork was disabled for the organization, so members can no longer let Haijun approve its own actions after a safety check.

  • type: optional "org_cowork_auto_mode_disabled"

default: org_cowork_auto_mode_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkAutoModeEnabled object

The "Auto" permission mode in Cowork was enabled for the organization, allowing members to let Haijun approve its own actions after a safety check.

  • type: optional "org_cowork_auto_mode_enabled"

default: org_cowork_auto_mode_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkBrowserPaneDisabled object

The in-app browser in Cowork was disabled for the organization, so Haijun can no longer open or use websites in a browser pane during members' Cowork sessions.

  • type: optional "org_cowork_browser_pane_disabled"

default: org_cowork_browser_pane_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkBrowserPaneEnabled object

The in-app browser in Cowork was enabled for the organization, letting Haijun open and use websites in a browser pane during members' Cowork sessions.

  • type: optional "org_cowork_browser_pane_enabled"

default: org_cowork_browser_pane_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkDisabled object

Organization cowork was disabled.

  • type: optional "org_cowork_disabled"

default: org_cowork_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgCoworkEnabled object

Organization cowork was enabled.

  • type: optional "org_cowork_enabled"

default: org_cowork_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgCoworkMcpAlwaysAllowDisabled object

The "Always allow" option for connector tools in Cowork was disabled for the organization, so each use of a connector tool that can make changes requires approval. Read-only connector tools are not affected by this setting.

  • type: optional "org_cowork_mcp_always_allow_disabled"

default: org_cowork_mcp_always_allow_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkMcpAlwaysAllowEnabled object

The "Always allow" option for connector tools in Cowork was enabled for the organization, letting members approve a connector tool that can make changes once and allow its later uses automatically. Read-only connector tools are not affected by this setting.

  • type: optional "org_cowork_mcp_always_allow_enabled"

default: org_cowork_mcp_always_allow_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkOtlpSettingsUpdated object

The organization's Cowork OpenTelemetry monitoring export settings were updated.

  • type: optional "org_cowork_otlp_settings_updated"

default: org_cowork_otlp_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • new_otlp_content_capture: optional array of string or null

The organization's content-capture settings after the change, as a sorted list of category names. An empty list means content capture is explicitly turned off. Null if the settings are not set or were not modified by this update.

  • new_otlp_endpoint: optional string or null

The OpenTelemetry export endpoint after the change. Credentials in the URL userinfo or query string are removed; path segments are retained. Null if the endpoint is unset or was not itself modified by this update.

  • new_otlp_protocol: optional string or null

The OpenTelemetry export protocol after the change. Null if the protocol is unset or was not itself modified by this update.

  • new_otlp_resource_attributes: optional string or null

The OpenTelemetry resource attributes after the change. Null if the attributes are unset or were not themselves modified by this update.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • otlp_headers_change: optional "cleared" or "set" or "unspecified" or null

Whether the OpenTelemetry export headers were set or cleared. 'set' is recorded for any non-empty submission, including resubmission of an unchanged value. Header values are never included.

  • "cleared"
  • "set"
  • "unspecified"
  • previous_otlp_content_capture: optional array of string or null

The organization's content-capture settings before the change, as a sorted list of category names. An empty list means content capture is explicitly turned off. Null if the settings were not previously set or were not modified by this update.

  • previous_otlp_endpoint: optional string or null

The OpenTelemetry export endpoint before the change. Credentials in the URL userinfo or query string are removed; path segments are retained. Null if the endpoint was previously unset or was not itself modified by this update.

  • previous_otlp_protocol: optional string or null

The OpenTelemetry export protocol before the change. Null if the protocol was previously unset or was not itself modified by this update.

  • previous_otlp_resource_attributes: optional string or null

The OpenTelemetry resource attributes before the change. Null if the attributes were previously unset or were not themselves modified by this update.

  • OrgCoworkRemoteDisabled object

Running Cowork in the cloud was disabled for the organization, so members can no longer run Cowork sessions in Juglow-hosted remote environments.

  • type: optional "org_cowork_remote_disabled"

default: org_cowork_remote_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCoworkRemoteEnabled object

Running Cowork in the cloud was enabled for the organization, allowing members to run Cowork sessions in Juglow-hosted remote environments.

  • type: optional "org_cowork_remote_enabled"

default: org_cowork_remote_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgCreationBlocked object

Organization creation was blocked.

  • type: optional "org_creation_blocked"

default: org_creation_blocked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • reason: optional string or null

"blocked" when the organization started preventing users with an email address at one of its verified domains from creating new organizations, "unblocked" when it stopped.

  • OrgDataExportAccessed object

Organization data export file was accessed/downloaded via signed URL.

  • type: optional "org_data_export_accessed"

default: org_data_export_accessed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • export_type: optional "conversations" or "unspecified" or "workbench" or null

Which data set was downloaded. Absent on records written before this field was introduced.

  • "conversations"
  • "unspecified"
  • "workbench"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDataExportCompleted object

Organization data export was completed.

  • type: optional "org_data_export_completed"

default: org_data_export_completed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • export_type: optional "conversations" or "unspecified" or "workbench" or null

Which data set was exported. Absent on records written before this field was introduced.

  • "conversations"
  • "unspecified"
  • "workbench"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDataExportStarted object

Organization data export was started.

  • type: optional "org_data_export_started"

default: org_data_export_started

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • export_type: optional "conversations" or "unspecified" or "workbench" or null

Which data set was exported. Absent on records written before this field was introduced.

  • "conversations"
  • "unspecified"
  • "workbench"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scope: optional "member_own_data" or "organization" or "unspecified" or null

Breadth of the export — the whole organization, or only the requesting member's own data. Absent on records written before this field was introduced.

  • "member_own_data"
  • "organization"
  • "unspecified"
  • OrgDataResidencyUpdated object

The organization's inference data residency settings were updated.

  • type: optional "org_data_residency_updated"

default: org_data_residency_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "allowed_inference_geos" or "default_inference_geo" or "unspecified"

The data residency setting that changed

  • "allowed_inference_geos"
  • "default_inference_geo"
  • "unspecified"
  • current_value: optional string or null

Setting value immediately after this change. For allowed_inference_geos: a comma-separated list of geo codes (e.g. 'global,us'), or the literal 'unrestricted'. For default_inference_geo: a single geo code.

  • previous_value: optional string or null

Setting value immediately before this change. For allowed_inference_geos: a comma-separated list of geo codes (e.g. 'global,us'), or the literal 'unrestricted'. For default_inference_geo: a single geo code.

  • OrgDeletedViaBulk object

Organization was deleted via bulk operation.

  • type: optional "org_deleted_via_bulk"

default: org_deleted_via_bulk

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDeletionRequested object

Organization deletion was requested.

  • type: optional "org_deletion_requested"

default: org_deletion_requested

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDirectoryResyncCompleted object

Organization directory resync completed successfully.

  • type: optional "org_directory_resync_completed"

default: org_directory_resync_completed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resync_uuid: string

UUID identifying the directory resync run that completed.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDirectoryResyncFailed object

Organization directory resync failed.

  • type: optional "org_directory_resync_failed"

default: org_directory_resync_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resync_uuid: string

UUID identifying the directory resync run that failed.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDirectoryResyncStarted object

Organization directory resync was started asynchronously.

  • type: optional "org_directory_resync_started"

default: org_directory_resync_started

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resync_uuid: string

UUID identifying this directory resync run

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • sync_destinations: optional array of string

Sync destinations the resync targets (for example, accounts and rbac)

  • OrgDirectorySyncActivated object

Organization directory sync was activated.

  • type: optional "org_directory_sync_activated"

default: org_directory_sync_activated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDirectorySyncAddInitiated object

Organization directory sync setup was initiated.

  • type: optional "org_directory_sync_add_initiated"

default: org_directory_sync_add_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDirectorySyncDeleted object

Organization directory sync was deleted.

  • type: optional "org_directory_sync_deleted"

default: org_directory_sync_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDiscoverabilityDisabled object

Admin disabled organization discoverability.

  • type: optional "org_discoverability_disabled"

default: org_discoverability_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDiscoverabilityEnabled object

Admin enabled organization discoverability.

  • type: optional "org_discoverability_enabled"

default: org_discoverability_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDiscoverabilitySettingsUpdated object

Admin updated organization discoverability settings.

  • type: optional "org_discoverability_settings_updated"

default: org_discoverability_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDomainAddInitiated object

Organization domain verification was initiated.

  • type: optional "org_domain_add_initiated"

default: org_domain_add_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDomainRemoved object

Organization domain was removed.

  • type: optional "org_domain_removed"

default: org_domain_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • domain: optional string or null

The email domain that was removed from the organization, e.g. "example.com".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgDomainVerified object

Organization domain was verified.

  • type: optional "org_domain_verified"

default: org_domain_verified

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • domain: optional string or null

The email domain that was verified for the organization, e.g. "example.com".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgExternalKeyCreated object

A CMEK external key config was created.

  • type: optional "org_external_key_created"

default: org_external_key_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • external_key_id: string

Tagged ID of the created external key config

  • provider: "aws" or "azure" or "gcp" or "unspecified"

KMS provider backing the key

  • "aws"
  • "azure"
  • "gcp"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgExternalKeyDeleted object

A CMEK external key config was deleted.

  • type: optional "org_external_key_deleted"

default: org_external_key_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • external_key_id: string

Tagged ID of the deleted external key config

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgExternalKeyUpdated object

A CMEK external key config was updated.

  • type: optional "org_external_key_updated"

default: org_external_key_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • external_key_id: string

Tagged ID of the updated external key config

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "display_name" or "geo" or "provider_config" or "unspecified"

The external key config field that changed

  • "display_name"
  • "geo"
  • "provider_config"
  • "unspecified"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • OrgExternalKeyValidated object

A CMEK external key config was validated against the customer's KMS.

  • type: optional "org_external_key_validated"

default: org_external_key_validated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • external_key_id: string

Tagged ID of the validated external key config

  • validation_result: "failure" or "success" or "unspecified"

Outcome of the encrypt/decrypt roundtrip

  • "failure"
  • "success"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgHipaaSelfServeEnabled object

A primary owner click-accepted the BAA and enabled HIPAA protections for the organization via the self-serve flow.

  • type: optional "org_hipaa_self_serve_enabled"

default: org_hipaa_self_serve_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • baa_content_hash: string

SHA-256 digest (hex) of the Business Associate Agreement that was accepted.

  • baa_version_label: string

Version label of the Business Associate Agreement that was accepted, e.g. "2026-05-06".

  • setup_guide_content_hash: string

SHA-256 digest (hex) of the HIPAA setup guide that was current when HIPAA protections were enabled.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgIPRestrictionCreated object

Organization IP restriction was created.

  • type: optional "org_ip_restriction_created"

default: org_ip_restriction_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgIPRestrictionDeleted object

Organization IP restriction was deleted.

  • type: optional "org_ip_restriction_deleted"

default: org_ip_restriction_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgIPRestrictionUpdated object

Organization IP restriction was updated.

  • type: optional "org_ip_restriction_updated"

default: org_ip_restriction_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgInviteLinkDisabled object

Organization invite link was disabled.

  • type: optional "org_invite_link_disabled"

default: org_invite_link_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgInviteLinkGenerated object

Organization invite link was generated.

  • type: optional "org_invite_link_generated"

default: org_invite_link_generated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgInviteLinkRegenerated object

Organization invite link was regenerated (previous link invalidated).

  • type: optional "org_invite_link_regenerated"

default: org_invite_link_regenerated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgInviteViewed object

An organization invite was viewed.

  • type: optional "org_invite_viewed"

default: org_invite_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • invite_id: string

Tagged ID of the viewed invite

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgInvitesListed object

Organization invites were listed.

  • type: optional "org_invites_listed"

default: org_invites_listed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgJoinProposalDecided object

Approve or reject decision on a parent-org join proposal.

  • type: optional "org_join_proposal_decided"

default: org_join_proposal_decided

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • approved: boolean
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgJoinRequestApproved object

Admin approved a join request.

  • type: optional "org_join_request_approved"

default: org_join_request_approved

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgJoinRequestCreated object

User requested to join an organization.

  • type: optional "org_join_request_created"

default: org_join_request_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgJoinRequestDismissed object

Admin dismissed a join request.

  • type: optional "org_join_request_dismissed"

default: org_join_request_dismissed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgJoinRequestInstantApproved object

Join request was instantly approved.

  • type: optional "org_join_request_instant_approved"

default: org_join_request_instant_approved

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgJoinRequestsBulkDismissed object

Admin bulk-dismissed join requests.

  • type: optional "org_join_requests_bulk_dismissed"

default: org_join_requests_bulk_dismissed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgMagicLinkSecondFactorToggled object

Organization magic link second factor was toggled.

  • type: optional "org_magic_link_second_factor_toggled"

default: org_magic_link_second_factor_toggled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enabled: boolean

Whether members signing in with SSO must also complete a magic link as a second factor, after this change.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgMemberInvitesDisabled object

Admin disabled member invites for the organization.

  • type: optional "org_member_invites_disabled"

default: org_member_invites_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgMemberInvitesEnabled object

Admin enabled member invites for the organization.

  • type: optional "org_member_invites_enabled"

default: org_member_invites_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgMembersExported object

Organization members list was exported as CSV.

  • type: optional "org_members_exported"

default: org_members_exported

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgModelDefaultUpdated object

An organization or role default model setting was changed by an administrator.

  • type: optional "org_model_default_updated"

default: org_model_default_updated

  • action: "cleared" or "set" or "unspecified"

Whether the default model was set or cleared

  • "cleared"
  • "set"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • override_user_selection: boolean

Whether the default is enforced as a fixed default, resetting members' own model selections at the start of each new conversation

  • principal_id: string

Tagged ID of the organization or role the default applies to

  • principal_type: "org" or "rbac_role" or "unspecified"

Whether the default applies to the whole organization or to a single role

  • "org"
  • "rbac_role"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • default_model: optional string or null

The model set as the default, when the action is set

  • model_access: optional array of object

The per-model access overrides set for this principal; absent when no overrides are configured

  • api_name: string

The model the decision applies to

  • enabled: boolean

Whether members with this principal may select the model

  • max_effort_level: optional string or null

The highest effort level members may select for this model, when capped

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgParentJoinProposalCreated object

Organization parent join proposal was created.

  • type: optional "org_parent_join_proposal_created"

default: org_parent_join_proposal_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgParentSearchPerformed object

Organization parent search was performed.

  • type: optional "org_parent_search_performed"

default: org_parent_search_performed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSSOAddInitiated object

Organization SSO setup was initiated.

  • type: optional "org_sso_add_initiated"

default: org_sso_add_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSSOConnectionActivated object

Organization SSO connection was activated.

  • type: optional "org_sso_connection_activated"

default: org_sso_connection_activated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • connection_id: optional string or null

Identifier of the SSO connection that was activated.

  • connection_type: optional string or null

The type of SSO connection that was activated, e.g. "OktaSAML" or "GenericOIDC".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSSOConnectionDeactivated object

Organization SSO connection was deactivated.

  • type: optional "org_sso_connection_deactivated"

default: org_sso_connection_deactivated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • connection_id: optional string or null

Identifier of the SSO connection that was deactivated.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSSOConnectionDeleted object

Organization SSO connection was deleted.

  • type: optional "org_sso_connection_deleted"

default: org_sso_connection_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • connection_id: optional string or null

Identifier of the SSO connection that was deleted.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSSOGroupRoleMappingsUpdated object

Organization SSO group role mappings were updated.

  • type: optional "org_sso_group_role_mappings_updated"

default: org_sso_group_role_mappings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSSOProvisioningModeChanged object

Organization SSO provisioning mode was changed.

  • type: optional "org_sso_provisioning_mode_changed"

default: org_sso_provisioning_mode_changed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • new_mode: optional string or null

The SSO provisioning mode after this change, e.g. "LOGIN_ONLY", "JIT_PERMISSIVE", "JIT_ADVANCED", "SCIM_PERMISSIVE", or "SCIM_ADVANCED".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_mode: optional string or null

The SSO provisioning mode before this change, e.g. "LOGIN_ONLY", "JIT_PERMISSIVE", "JIT_ADVANCED", "SCIM_PERMISSIVE", or "SCIM_ADVANCED".

  • OrgSSOScimWelcomeEmailToggled object

Organization SCIM-provisioned welcome email was toggled.

  • type: optional "org_sso_scim_welcome_email_toggled"

default: org_sso_scim_welcome_email_toggled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enabled: boolean

Whether the SCIM welcome email is enabled after this change.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_enabled: optional boolean or null

Whether the SCIM welcome email was enabled before this change.

  • OrgSSOSeatTierAssignmentToggled object

Organization SSO seat tier assignment was toggled.

  • type: optional "org_sso_seat_tier_assignment_toggled"

default: org_sso_seat_tier_assignment_toggled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enabled: boolean

Whether SSO seat tier assignment is enabled after this change.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_enabled: optional boolean or null

Whether SSO seat tier assignment was enabled before this change.

  • OrgSSOSeatTierMappingsUpdated object

Organization SSO seat tier mappings were updated.

  • type: optional "org_sso_seat_tier_mappings_updated"

default: org_sso_seat_tier_mappings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_mappings: optional array of object or null

Identity provider group to seat tier mappings after this change.

  • idp_group_name: string

Name of the identity provider group.

  • seat_tier: optional string or null

Seat tier assigned to members of the identity provider group, or null if the mapping assigns no seat.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_mappings: optional array of object or null

Identity provider group to seat tier mappings before this change.

  • idp_group_name: string

Name of the identity provider group.

  • seat_tier: optional string or null

Seat tier assigned to members of the identity provider group, or null if the mapping assigns no seat.

  • OrgSSOToggled object

Organization SSO was toggled on or off.

  • type: optional "org_sso_toggled"

default: org_sso_toggled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enabled: boolean

Whether SSO login is enforced after this change.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSyncDeletingSynchronizedFilesStarted object

Organization started deleting synchronized files.

  • type: optional "org_sync_deleting_synchronized_files_started"

default: org_sync_deleting_synchronized_files_started

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgSyncSynchronizedFilesDeleted object

Organization synchronized files were deleted.

  • type: optional "org_sync_synchronized_files_deleted"

default: org_sync_synchronized_files_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgTaintAdded object

A taint was added to an organization.

  • type: optional "org_taint_added"

default: org_taint_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • taint: optional string or null

The taint that was added, for example the HIPAA taint.

  • workspace_id: optional string or null

Tagged ID of the workspace the taint was applied to. Unset when applied at organization scope.

  • OrgTaintRemoved object

A taint was removed from an organization.

  • type: optional "org_taint_removed"

default: org_taint_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • taint: optional string or null

The taint that was removed, for example the HIPAA taint.

  • OrgUserDeleted object

User was removed from organization.

  • type: optional "org_user_deleted"

default: org_user_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • deleted_user_email: optional string or null

Email address of the member who was removed, when known.

  • deleted_user_id: optional string or null

Tagged ID of the member who was removed from the organization, e.g. "user_01HX...".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgUserInviteAccepted object

Organization user invite was accepted.

  • type: optional "org_user_invite_accepted"

default: org_user_invite_accepted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • invite_id: optional string or null

Tagged ID of the invite that was accepted.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • rbac_group_ids: optional array of string or null

RBAC group IDs the user was added to on acceptance, as confirmed by the group service (absent on rows written before this was recorded, and when the invite carried no groups)

  • OrgUserInviteDeleted object

Organization user invite was deleted.

  • type: optional "org_user_invite_deleted"

default: org_user_invite_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • invite_id: optional string or null

Tagged ID of the invite that was deleted.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgUserInviteReSent object

Organization user invite was re-sent.

  • type: optional "org_user_invite_re_sent"

default: org_user_invite_re_sent

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • invited_email: optional string or null

Email address the invite was re-sent to.

  • invited_role: optional string or null

Role the invited user will receive on joining

  • invited_seat_tier: optional string or null

Seat tier the invited user will receive on joining

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgUserInviteRejected object

Organization user invite was rejected.

  • type: optional "org_user_invite_rejected"

default: org_user_invite_rejected

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • invite_id: optional string or null

Tagged ID of the invite that was rejected.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgUserInviteSent object

Organization user invite was sent.

  • type: optional "org_user_invite_sent"

default: org_user_invite_sent

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • invited_email: optional string or null

Email address the invite was sent to.

  • invited_rbac_group_ids: optional array of string or null

RBAC group IDs the invited user will be added to on joining

  • invited_role: optional string or null

Role the invited user will receive on joining.

  • invited_seat_tier: optional string or null

Seat tier the invited user will receive on joining

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgUserLeft object

User removed themselves from organization.

  • type: optional "org_user_left"

default: org_user_left

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_role: optional string or null

The role the member held in the organization before leaving, e.g. "user" or "admin".

  • OrgUserSharesRetained object

A member left or was removed from the organization while projects, tracks, plugins, or chats they had shared were still shared, and those shares were kept.

  • type: optional "org_user_shares_retained"

default: org_user_shares_retained

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resource_count: number

Number of distinct resources the member had shared that are still shared, counted up to a fixed limit, so a lower bound when truncated is true; it can exceed the number of IDs listed below.

  • share_count: number

Number of shares kept across those resources (one per audience a resource is shared with), counted up to the same limit, so a lower bound when truncated is true.

  • truncated: boolean

True when the ID lists do not include every still-shared resource or the counts stopped at their limit.

  • user_id: string

Tagged ID of the member who left or was removed.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_chat_ids: optional array of string

Tagged IDs of chats among those resources.

  • haijun_project_ids: optional array of string

Tagged IDs of projects among those resources; the four ID lists hold at most the first 50 resources between them.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_ids: optional array of string

Tagged IDs of plugins among those resources.

  • skill_ids: optional array of string

Tagged IDs of tracks among those resources.

  • OrgUserTrustedDevicesRevoked object

An organization admin revoked a member's trusted devices and signed the member out of all active sessions.

  • type: optional "org_user_trusted_devices_revoked"

default: org_user_trusted_devices_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • completed: boolean

Whether the operation completed fully. False records an attempt that revoked the counted credentials but failed before finishing.

  • devices_revoked_count: number

Number of trusted devices revoked

  • sessions_revoked_count: number

Number of active sessions the member was signed out of

  • user_id: string

Tagged ID of the member whose trusted devices were revoked

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgUserViewed object

An organization user was viewed.

  • type: optional "org_user_viewed"

default: org_user_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string

Tagged ID of the viewed user

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgUsersListed object

Organization users were listed.

  • type: optional "org_users_listed"

default: org_users_listed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrgWorkAcrossAppsDisabled object

The organization's "Let Haijun work across apps" setting was turned off.

  • type: optional "org_work_across_apps_disabled"

default: org_work_across_apps_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrgWorkAcrossAppsEnabled object

The organization's "Let Haijun work across apps" setting was turned on.

  • type: optional "org_work_across_apps_enabled"

default: org_work_across_apps_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_value: optional boolean or null

Setting value immediately after this change

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrganizationAddressUpdated object

The organization's billing or shipping address was updated.

  • type: optional "organization_address_updated"

default: organization_address_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • billing_address_updated: optional boolean or null

Whether the billing address was updated.

  • billing_name_updated: optional boolean or null

Whether the billing name was updated.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • shipping_address_updated: optional boolean or null

Whether the shipping address was updated.

  • shipping_name_updated: optional boolean or null

Whether the shipping name was updated.

  • OrganizationIconDeleted object

Organization's custom icon deleted.

  • type: optional "organization_icon_deleted"

default: organization_icon_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OrganizationIconUpdated object

Organization's custom icon uploaded or replaced.

  • type: optional "organization_icon_updated"

default: organization_icon_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunOrganizationSettingsUpdated object

Organization settings were updated.

  • type: optional "haijun_organization_settings_updated"

default: haijun_organization_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • updates: array of Name or Capabilities or RedactContent or 96 more
  • Name object

The organization name setting was changed.

  • type: optional "name"

default: name

  • current_value: optional string or null

Setting value immediately after this change

  • previous_value: optional string or null

Setting value immediately before this change

  • Capabilities object

The organization capabilities setting was changed.

  • type: optional "capabilities"

default: capabilities

  • current_value: optional array of string or null

Setting value immediately after this change

  • previous_value: optional array of string or null

Setting value immediately before this change

  • RedactContent object

The organization content-redaction setting was changed.

  • type: optional "redact_content"

default: redact_content

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • PublicProjectsEnabled object

The public projects setting was changed for the organization.

  • type: optional "public_projects_enabled"

default: public_projects_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • WebSearchEnabled object

The web search setting was changed.

  • type: optional "web_search_enabled"

default: web_search_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • GeolocationEnabled object

The geolocation setting was changed.

  • type: optional "geolocation_enabled"

default: geolocation_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • EnabledSaffron object

The memory setting was changed for the organization.

  • type: optional "enabled_saffron"

default: enabled_saffron

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • DataRetentionPeriods object

The data retention periods setting was changed for the organization.

  • type: optional "data_retention_periods"

default: data_retention_periods

  • current_value: optional array of object or null

Setting value immediately after this change

  • data_type: "all" or "artifact_private" or "artifact_shared" or 2 more
  • "all"
  • "artifact_private"
  • "artifact_shared"
  • "chat"
  • "project"
  • duration: number

minimum: -2147483648, maximum: 2147483647

  • timescale: "day" or "indefinite" or "month"
  • "day"
  • "indefinite"
  • "month"
  • previous_value: optional array of object or null

Setting value immediately before this change

  • data_type: "all" or "artifact_private" or "artifact_shared" or 2 more
  • "all"
  • "artifact_private"
  • "artifact_shared"
  • "chat"
  • "project"
  • duration: number

minimum: -2147483648, maximum: 2147483647

  • timescale: "day" or "indefinite" or "month"
  • "day"
  • "indefinite"
  • "month"
  • MembersLimit object

The members limit setting was changed for the organization.

  • type: optional "members_limit"

default: members_limit

  • current_value: optional number or null

Setting value immediately after this change

  • previous_value: optional number or null

Setting value immediately before this change

  • HaijunAPIInArtifactsEnabled object

The Haijun API in Artifacts setting was changed.

  • type: optional "haijun_api_in_artifacts_enabled"

default: haijun_api_in_artifacts_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • SupportContactMode object

The support contact routing mode setting was changed for the organization.

  • type: optional "support_contact_mode"

default: support_contact_mode

  • current_value: optional "ai_support_only" or "human_support_restricted" or "unspecified" or null

Setting value immediately after this change

  • "ai_support_only"
  • "human_support_restricted"
  • "unspecified"
  • previous_value: optional "ai_support_only" or "human_support_restricted" or "unspecified" or null

Setting value immediately before this change

  • "ai_support_only"
  • "human_support_restricted"
  • "unspecified"
  • SupportContactAlwaysIncludeAdminsOwners object

The support contact always-include-admins-owners setting was changed for the organization.

  • type: optional "support_contact_always_include_admins_owners"

default: support_contact_always_include_admins_owners

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • SupportContactDesignatedGroups object

The support contact designated groups setting was changed for the organization.

  • type: optional "support_contact_designated_groups"

default: support_contact_designated_groups

  • current_value: optional array of string or null

Setting value immediately after this change

  • previous_value: optional array of string or null

Setting value immediately before this change

  • SubscriptionItemQuotas object

The organization's subscription seat quotas were changed.

  • type: optional "subscription_item_quotas"

default: subscription_item_quotas

  • current_value: optional map[number] or null

Seat-type to quantity mapping immediately after this change. A null quantity means the item is unlimited/unmetered.

  • previous_value: optional map[number] or null

Seat-type to quantity mapping immediately before this change. A null quantity means the item was unlimited/unmetered.

  • MembersBulkSeatTierAssignment object

All organization members were assigned the specified seat tier.

  • type: optional "members_bulk_seat_tier_assignment"

default: members_bulk_seat_tier_assignment

  • current_value: optional string or null

The seat tier every member was assigned to

  • member_count: optional number or null

Number of members whose seat tier was changed

  • previous_value: optional string or null

Not populated; members may have held differing seat tiers before the bulk assignment

  • HaijunCodeWebEnabled object

The Haijun Code cloud sessions setting was changed for the organization.

  • type: optional "haijun_code_web_enabled"

default: haijun_code_web_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeDesktopBypassPermissionsEnabled object

The Haijun Code Desktop bypass-permissions mode setting was changed for the organization.

  • type: optional "haijun_code_desktop_bypass_permissions_enabled"

default: haijun_code_desktop_bypass_permissions_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeDesktopAutoPermissionsEnabled object

The Haijun Code Desktop auto-permissions mode setting was changed for the organization.

  • type: optional "haijun_code_desktop_auto_permissions_enabled"

default: haijun_code_desktop_auto_permissions_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • SkillsEnabled object

The Haijun.ai tracks setting was changed for the organization.

  • type: optional "skills_enabled"

default: skills_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • WorkbenchCompletionFeedbackEnabled object

The Workbench completion feedback setting was changed for the organization.

  • type: optional "workbench_completion_feedback_enabled"

default: workbench_completion_feedback_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAICompletionFeedbackEnabled object

The Haijun.ai completion feedback setting was changed for the organization.

  • type: optional "haijun_ai_completion_feedback_enabled"

default: haijun_ai_completion_feedback_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAIIntegrationSharingEnabled object

The Haijun.ai integration sharing setting was changed for the organization.

  • type: optional "haijun_ai_integration_sharing_enabled"

default: haijun_ai_integration_sharing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAIChatSharingEnabled object

The Haijun.ai chat sharing setting was changed for the organization.

  • type: optional "haijun_ai_chat_sharing_enabled"

default: haijun_ai_chat_sharing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAICcrSharingEnabled object

The Haijun.ai remote Haijun Code session sharing setting was changed for the organization.

  • type: optional "haijun_ai_ccr_sharing_enabled"

default: haijun_ai_ccr_sharing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAICcrSupportSharingEnabled object

The Juglow support access setting for Haijun Code sessions was changed for the organization.

  • type: optional "haijun_ai_ccr_support_sharing_enabled"

default: haijun_ai_ccr_support_sharing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • BatchesDownloadUiVisibility object

The batches download UI visibility setting was changed for the organization.

  • type: optional "batches_download_ui_visibility"

default: batches_download_ui_visibility

  • current_value: optional "all" or "none" or "selected" or "unspecified" or null

Setting value immediately after this change

  • "all"
  • "none"
  • "selected"
  • "unspecified"
  • previous_value: optional "all" or "none" or "selected" or "unspecified" or null

Setting value immediately before this change

  • "all"
  • "none"
  • "selected"
  • "unspecified"
  • AllowedInviteDomains object

The allowed invite domains setting was changed for the organization.

  • type: optional "allowed_invite_domains"

default: allowed_invite_domains

  • current_value: optional array of string or null

Setting value immediately after this change

  • previous_value: optional array of string or null

Setting value immediately before this change

  • WebSearchAPISettings object

The web search API setting was changed for the organization.

  • type: optional "web_search_api_settings"

default: web_search_api_settings

  • current_value: optional object or null

Setting value immediately after this change

  • domain_filters: object or null

Allowed/blocked domain filters shared by web_search and web_fetch tools.

  • allowed_domains: optional array of string or null
  • blocked_domains: optional array of string or null
  • is_enabled: boolean
  • previous_value: optional object or null

Setting value immediately before this change

  • domain_filters: object or null

Allowed/blocked domain filters shared by web_search and web_fetch tools.

  • allowed_domains: optional array of string or null
  • blocked_domains: optional array of string or null
  • is_enabled: boolean
  • WebFetchAPISettings object

The web fetch API setting was changed for the organization.

  • type: optional "web_fetch_api_settings"

default: web_fetch_api_settings

  • current_value: optional object or null

Setting value immediately after this change

  • domain_filters: object or null

Allowed/blocked domain filters shared by web_search and web_fetch tools.

  • allowed_domains: optional array of string or null
  • blocked_domains: optional array of string or null
  • is_enabled: boolean
  • previous_value: optional object or null

Setting value immediately before this change

  • domain_filters: object or null

Allowed/blocked domain filters shared by web_search and web_fetch tools.

  • allowed_domains: optional array of string or null
  • blocked_domains: optional array of string or null
  • is_enabled: boolean
  • DefaultWorkspaceSettings object

The default workspace setting was changed for the organization.

  • type: optional "default_workspace_settings"

default: default_workspace_settings

  • current_value: optional object or null

Setting value immediately after this change

  • enable_api_keys: optional boolean

default: true

  • previous_value: optional object or null

Setting value immediately before this change

  • enable_api_keys: optional boolean

default: true

  • BatchesDownloadUiEnabledWorkspaceIDs object

The batches download UI enabled workspace IDs setting was changed for the organization.

  • type: optional "batches_download_ui_enabled_workspace_ids"

default: batches_download_ui_enabled_workspace_ids

  • current_value: optional array of string or null

Setting value immediately after this change

  • previous_value: optional array of string or null

Setting value immediately before this change

  • HaijunCodeManagedSettings object

The organization's Haijun Code managed settings were changed.

The full previous and current settings content is provided in the previous_value and current_value fields.

  • type: optional "haijun_code_managed_settings"

default: haijun_code_managed_settings

  • current_value: optional map[unknown] or null
  • current_version: optional number or null
  • previous_value: optional map[unknown] or null
  • previous_version: optional number or null
  • settings_uuid: optional string or null
  • AccountSessionDurationSeconds object

Tracks changes to the enterprise account session duration setting (in seconds).

  • type: optional "account_session_duration_seconds"

default: account_session_duration_seconds

  • current_value: optional number or null

Setting value immediately after this change

  • previous_value: optional number or null

Setting value immediately before this change

  • VcsConnections object

Tracks changes to VCS (GitHub, etc.) organization connections.

  • type: optional "vcs_connections"

default: vcs_connections

  • current_value: optional array of object or null

Setting value immediately after this change

  • type: "github"

Supported Version Control System providers.

  • org_name: string
  • metadata: optional map[string] or null
  • org_id: optional string or null
  • previous_value: optional array of object or null

Setting value immediately before this change

  • type: "github"

Supported Version Control System providers.

  • org_name: string
  • metadata: optional map[string] or null
  • org_id: optional string or null
  • DisabledAdminRequestTypes object

Tracks changes to which admin request types are disabled.

  • type: optional "disabled_admin_request_types"

default: disabled_admin_request_types

  • current_value: optional array of string or null

Setting value immediately after this change

  • previous_value: optional array of string or null

Setting value immediately before this change

  • MemberUsageDashboardVisible object

The member usage dashboard visibility setting was changed for the organization.

  • type: optional "member_usage_dashboard_visible"

default: member_usage_dashboard_visible

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • CodeExecutionNetworkEgressEnabled object

The code execution network egress setting was changed for the organization.

  • type: optional "code_execution_network_egress_enabled"

default: code_execution_network_egress_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • CodeExecutionDomainAllowlistChanged object

The code execution domain allowlist setting was changed for the organization.

  • type: optional "code_execution_domain_allowlist_changed"

default: code_execution_domain_allowlist_changed

  • current_value: optional array of string or null

Setting value immediately after this change

  • previous_value: optional array of string or null

Setting value immediately before this change

  • CodeExecutionDomainAllowlistTemplateChanged object

The code execution domain allowlist template setting was changed for the organization.

  • type: optional "code_execution_domain_allowlist_template_changed"

default: code_execution_domain_allowlist_template_changed

  • current_value: optional "custom" or "full_egress" or "package_managers" or "unspecified" or null

Setting value immediately after this change

  • "custom"
  • "full_egress"
  • "package_managers"
  • "unspecified"
  • previous_value: optional "custom" or "full_egress" or "package_managers" or "unspecified" or null

Setting value immediately before this change

  • "custom"
  • "full_egress"
  • "package_managers"
  • "unspecified"
  • ChatEnabled object

The chat setting was changed for the organization.

  • type: optional "chat_enabled"

default: chat_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeQuickWebSetupEnabled object

The Haijun Code quick web setup setting was changed for the organization.

  • type: optional "haijun_code_quick_web_setup_enabled"

default: haijun_code_quick_web_setup_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeTeamMemoryMode object

The Haijun Code team memory mode setting was changed for the organization.

  • type: optional "haijun_code_team_memory_mode"

default: haijun_code_team_memory_mode

  • current_value: optional "all_org_members" or "github_repo" or "off" or 2 more or null

Setting value immediately after this change

  • "all_org_members"
  • "github_repo"
  • "off"
  • "specific_groups"
  • "unspecified"
  • previous_value: optional "all_org_members" or "github_repo" or "off" or 2 more or null

Setting value immediately before this change

  • "all_org_members"
  • "github_repo"
  • "off"
  • "specific_groups"
  • "unspecified"
  • BrowserExtensionSettings object

The browser extension setting was changed for the organization.

  • type: optional "browser_extension_settings"

default: browser_extension_settings

  • current_value: optional map[unknown] or null

Setting value immediately after this change

  • previous_value: optional map[unknown] or null

Setting value immediately before this change

  • IsDesktopExtensionAllowlistEnabled object

The desktop extension allowlist setting was changed for the organization.

  • type: optional "is_desktop_extension_allowlist_enabled"

default: is_desktop_extension_allowlist_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • AllowMemberDataExport object

The per-member self-serve data export setting was changed for the organization.

  • type: optional "allow_member_data_export"

default: allow_member_data_export

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAIDesignEnabled object

The Haijun Design setting was changed for the organization.

  • type: optional "haijun_ai_design_enabled"

default: haijun_ai_design_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceEnabled object

The setting that turns Haijun Science on or off for the organization was changed.

  • type: optional "haijun_science_enabled"

default: haijun_science_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceMemoryEnabled object

The Haijun Science memory setting was changed for the organization.

  • type: optional "haijun_science_memory_enabled"

default: haijun_science_memory_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceCustomConnectorsEnabled object

The Haijun Science custom connectors setting was changed for the organization.

  • type: optional "haijun_science_custom_connectors_enabled"

default: haijun_science_custom_connectors_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceCustomSkillsEnabled object

The Haijun Science custom tracks setting was changed for the organization.

  • type: optional "haijun_science_custom_skills_enabled"

default: haijun_science_custom_skills_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceManagedNetworkAllowlistEnabled object

The Haijun Science setting that puts the network allowlist under the organization's management, instead of each member managing their own, was changed for the organization.

  • type: optional "haijun_science_managed_network_allowlist_enabled"

default: haijun_science_managed_network_allowlist_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceSSHHostsEnabled object

The Haijun Science SSH hosts setting was changed for the organization.

  • type: optional "haijun_science_ssh_hosts_enabled"

default: haijun_science_ssh_hosts_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceModalEnabled object

The Haijun Science setting that lets members connect Modal cloud compute was changed for the organization.

  • type: optional "haijun_science_modal_enabled"

default: haijun_science_modal_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceScientificModelEndpointsEnabled object

The Haijun Science scientific model endpoints setting was changed for the organization.

  • type: optional "haijun_science_scientific_model_endpoints_enabled"

default: haijun_science_scientific_model_endpoints_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceNetworkAllowlistChanged object

The hostnames on the organization's Haijun Science network allowlist, which applies to members while the organization manages the allowlist, were changed.

  • type: optional "haijun_science_network_allowlist_changed"

default: haijun_science_network_allowlist_changed

  • current_value: optional array of string or null

Setting value immediately after this change: the organization's complete saved allowlist (built-in and custom domains alike) as lowercase hostnames, each optionally prefixed with '*.'. Null means no list is saved (this change reset it), so Haijun Science's built-in allowlist applies; an empty list means a list with no domains on it is saved.

  • previous_value: optional array of string or null

Setting value immediately before this change: the organization's complete saved allowlist (built-in and custom domains alike) as lowercase hostnames, each optionally prefixed with '*.'. Null means no list was saved at that point (never saved, or since reset), so Haijun Science's built-in allowlist applied; an empty list means a list with no domains on it had been saved.

  • HaijunScienceModalWorkspaceAllowlistChanged object

The Haijun Science Modal cloud compute workspace allowlist setting was changed for the organization.

  • type: optional "haijun_science_modal_workspace_allowlist_changed"

default: haijun_science_modal_workspace_allowlist_changed

  • current_value: optional array of string or null

Setting value immediately after this change: the Modal workspace names members can connect to. Null or an empty list means any workspace is allowed.

  • previous_value: optional array of string or null

Setting value immediately before this change: the Modal workspace names members could connect to. Null or an empty list means any workspace was allowed.

  • HaijunSciencePackageMirrorCondaChannelChanged object

The Haijun Science package mirror setting for the conda channel was changed for the organization.

  • type: optional "haijun_science_package_mirror_conda_channel_changed"

default: haijun_science_package_mirror_conda_channel_changed

  • current_value: optional string or null

Setting value immediately after this change: the HTTPS URL of the organization's conda channel mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none is set.

  • previous_value: optional string or null

Setting value immediately before this change: the HTTPS URL of the organization's conda channel mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none was set.

  • HaijunSciencePackageMirrorPipIndexChanged object

The Haijun Science package mirror setting for the Python package index was changed for the organization.

  • type: optional "haijun_science_package_mirror_pip_index_changed"

default: haijun_science_package_mirror_pip_index_changed

  • current_value: optional string or null

Setting value immediately after this change: the HTTPS URL of the organization's Python (pip) package index mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none is set.

  • previous_value: optional string or null

Setting value immediately before this change: the HTTPS URL of the organization's Python (pip) package index mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none was set.

  • HaijunAISkillPluginsScanningEnabled object

The track and plugin security scanning setting was changed for the organization.

  • type: optional "haijun_ai_skill_plugins_scanning_enabled"

default: haijun_ai_skill_plugins_scanning_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • ArtifactPublishingEnabled object

The Artifact publishing setting was changed for the organization.

  • type: optional "artifact_publishing_enabled"

default: artifact_publishing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • ArtifactExternalSharingEnabled object

The Artifact external sharing setting was changed for the organization.

  • type: optional "artifact_external_sharing_enabled"

default: artifact_external_sharing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • ArtifactPresenceEnabled object

The Artifact presence setting was changed for the organization.

  • type: optional "artifact_presence_enabled"

default: artifact_presence_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAISkillSharingEnabled object

The Haijun.ai track sharing setting was changed for the organization.

  • type: optional "haijun_ai_skill_sharing_enabled"

default: haijun_ai_skill_sharing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAISkillSharingOrgEnabled object

The Haijun.ai organization-wide track sharing setting was changed for the organization.

  • type: optional "haijun_ai_skill_sharing_org_enabled"

default: haijun_ai_skill_sharing_org_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAISkillSharingGroupEnabled object

The Haijun.ai group-based track sharing setting was changed for the organization.

  • type: optional "haijun_ai_skill_sharing_group_enabled"

default: haijun_ai_skill_sharing_group_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAISkillPublishPolicy object

The Haijun.ai organization track publish policy was changed for the organization.

  • type: optional "haijun_ai_skill_publish_policy"

default: haijun_ai_skill_publish_policy

  • current_value: optional "off" or "open" or "review" or "unspecified" or null

Setting value immediately after this change

  • "off"
  • "open"
  • "review"
  • "unspecified"
  • previous_value: optional "off" or "open" or "review" or "unspecified" or null

Setting value immediately before this change

  • "off"
  • "open"
  • "review"
  • "unspecified"
  • HaijunCodeRemoteControlEnabled object

The Haijun Code remote control setting was changed for the organization.

  • type: optional "haijun_code_remote_control_enabled"

default: haijun_code_remote_control_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeRemoteControlDefaultEnabled object

The Haijun Code remote control auto-enable default was changed for the organization.

  • type: optional "haijun_code_remote_control_default_enabled"

default: haijun_code_remote_control_default_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeRoutinesEnabled object

The Haijun Code routines setting was changed for the organization.

  • type: optional "haijun_code_routines_enabled"

default: haijun_code_routines_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeWorkflowsEnabled object

The Haijun Code Workflows setting was changed for the organization.

  • type: optional "haijun_code_workflows_enabled"

default: haijun_code_workflows_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • FrontierServicesDataUseEnabled object

The frontier services data use setting was changed for the organization.

  • type: optional "frontier_services_data_use_enabled"

default: frontier_services_data_use_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • LtiCourseProjectsEnabled object

The LTI course projects setting was changed for the organization.

  • type: optional "lti_course_projects_enabled"

default: lti_course_projects_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAISkillCreationEnabled object

The Haijun.ai track creation setting was changed for the organization.

  • type: optional "haijun_ai_skill_creation_enabled"

default: haijun_ai_skill_creation_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeGitHubAnalyticsEnabled object

The Haijun Code GitHub analytics setting was changed for the organization.

  • type: optional "haijun_code_github_analytics_enabled"

default: haijun_code_github_analytics_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeHideManagedEnvironments object

The Haijun Code hide managed environments setting was changed for the organization.

  • type: optional "haijun_code_hide_managed_environments"

default: haijun_code_hide_managed_environments

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeAllowSessionPoolMoves object

The Haijun Code allow session pool moves setting was changed for the organization.

  • type: optional "haijun_code_allow_session_pool_moves"

default: haijun_code_allow_session_pool_moves

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeDisableJuglowCompute object

The Haijun Code disable Juglow compute setting was changed for the organization.

  • type: optional "haijun_code_disable_juglow_compute"

default: haijun_code_disable_juglow_compute

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeMetricsLoggingEnabled object

The Haijun Code metrics logging setting was changed for the organization.

  • type: optional "haijun_code_metrics_logging_enabled"

default: haijun_code_metrics_logging_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeFastModeEnabled object

The Haijun Code fast mode setting was changed for the organization.

  • type: optional "haijun_code_fast_mode_enabled"

default: haijun_code_fast_mode_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunCodeTrustedDevicesRequired object

The Haijun Code trusted devices setting was changed for the organization.

  • type: optional "haijun_code_trusted_devices_required"

default: haijun_code_trusted_devices_required

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • CoworkTrustedDevicesRequired object

The Cowork trusted devices enforcement setting was changed for the organization.

  • type: optional "cowork_trusted_devices_required"

default: cowork_trusted_devices_required

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • InlineVisualizationsEnabled object

The inline visualizations setting was changed for the organization.

  • type: optional "inline_visualizations_enabled"

default: inline_visualizations_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • OrganizationBannerSettings object

The organization banner setting was changed.

  • type: optional "organization_banner_settings"

default: organization_banner_settings

  • current_value: optional map[unknown] or null

Setting value immediately after this change

  • previous_value: optional map[unknown] or null

Setting value immediately before this change

  • HaijunInSlackSettings object

The Haijun in Slack setting was changed for the organization.

  • type: optional "haijun_in_slack_settings"

default: haijun_in_slack_settings

  • current_value: optional map[unknown] or null

Setting value immediately after this change

  • previous_value: optional map[unknown] or null

Setting value immediately before this change

  • HaijunCodeDefaultWorkerEnvironmentID object

The Haijun Code default worker environment setting was changed for the organization.

  • type: optional "haijun_code_default_worker_environment_id"

default: haijun_code_default_worker_environment_id

  • current_value: optional string or null

Setting value immediately after this change

  • previous_value: optional string or null

Setting value immediately before this change

  • HaijunCodeDefaultWorkerPoolID object

The Haijun Code default worker pool setting was changed for the organization.

  • type: optional "haijun_code_default_worker_pool_id"

default: haijun_code_default_worker_pool_id

  • current_value: optional string or null

Setting value immediately after this change

  • previous_value: optional string or null

Setting value immediately before this change

  • ManagedAgentsEnabled object

The managed agents setting was changed for the organization.

  • type: optional "managed_agents_enabled"

default: managed_agents_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunScienceFeaturedConnectorsDefaultChanged object

The organization-wide default for Haijun Science featured connectors was changed for the organization.

  • type: optional "haijun_science_featured_connectors_default_changed"

default: haijun_science_featured_connectors_default_changed

  • current_value: optional boolean or null

Setting value immediately after this change: whether featured connectors not set individually are on for members. Null means no organization-wide default is set (this change removed it), so the plan default applies.

  • previous_value: optional boolean or null

Setting value immediately before this change: whether featured connectors not set individually were on for members. Null means no organization-wide default was set, so the plan default applied.

  • HaijunScienceFeaturedConnectorsEnabledListChanged object

The list of Haijun Science featured connectors individually turned on for members was changed for the organization.

  • type: optional "haijun_science_featured_connectors_enabled_list_changed"

default: haijun_science_featured_connectors_enabled_list_changed

  • current_value: optional array of string or null

Setting value immediately after this change: the ids of the featured connectors individually turned on. Null or an empty list means none.

  • previous_value: optional array of string or null

Setting value immediately before this change: the ids of the featured connectors individually turned on. Null or an empty list means none.

  • HaijunScienceFeaturedConnectorsDisabledListChanged object

The list of Haijun Science featured connectors individually turned off for members was changed for the organization.

  • type: optional "haijun_science_featured_connectors_disabled_list_changed"

default: haijun_science_featured_connectors_disabled_list_changed

  • current_value: optional array of string or null

Setting value immediately after this change: the ids of the featured connectors individually turned off. Null or an empty list means none.

  • previous_value: optional array of string or null

Setting value immediately before this change: the ids of the featured connectors individually turned off. Null or an empty list means none.

  • HaijunScienceFeaturedSkillsDefaultChanged object

The organization-wide default for Haijun Science featured tracks was changed for the organization.

  • type: optional "haijun_science_featured_skills_default_changed"

default: haijun_science_featured_skills_default_changed

  • current_value: optional boolean or null

Setting value immediately after this change: whether featured tracks not set individually are on for members. Null means no organization-wide default is set (this change removed it), so the plan default applies.

  • previous_value: optional boolean or null

Setting value immediately before this change: whether featured tracks not set individually were on for members. Null means no organization-wide default was set, so the plan default applied.

  • HaijunScienceFeaturedSkillsEnabledListChanged object

The list of Haijun Science featured tracks individually turned on for members was changed for the organization.

  • type: optional "haijun_science_featured_skills_enabled_list_changed"

default: haijun_science_featured_skills_enabled_list_changed

  • current_value: optional array of string or null

Setting value immediately after this change: the ids of the featured tracks individually turned on. Null or an empty list means none.

  • previous_value: optional array of string or null

Setting value immediately before this change: the ids of the featured tracks individually turned on. Null or an empty list means none.

  • HaijunScienceFeaturedSkillsDisabledListChanged object

The list of Haijun Science featured tracks individually turned off for members was changed for the organization.

  • type: optional "haijun_science_featured_skills_disabled_list_changed"

default: haijun_science_featured_skills_disabled_list_changed

  • current_value: optional array of string or null

Setting value immediately after this change: the ids of the featured tracks individually turned off. Null or an empty list means none.

  • previous_value: optional array of string or null

Setting value immediately before this change: the ids of the featured tracks individually turned off. Null or an empty list means none.

  • FilesAPIEnabled object

The Files API was turned on or off for the organization.

  • type: optional "files_api_enabled"

default: files_api_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • SkillsAPIEnabled object

The Tracks API was turned on or off for the organization.

  • type: optional "skills_api_enabled"

default: skills_api_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • PasswordManagerIntegrationEnabled object

The password manager integration setting was changed for the organization.

  • type: optional "password_manager_integration_enabled"

default: password_manager_integration_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • APIKeyCreationEnabled object

The setting that allows members to create new API keys was changed for the organization.

  • type: optional "api_key_creation_enabled"

default: api_key_creation_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAcademyInferenceEnabled object

The setting that lets members use Haijun in Haijun Academy was changed for the organization.

  • type: optional "haijun_academy_inference_enabled"

default: haijun_academy_inference_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAIProjectSharingEnabled object

The Haijun.ai project sharing setting (whether members can share projects with new recipients: people, groups, or the whole organization) was changed for the organization.

  • type: optional "haijun_ai_project_sharing_enabled"

default: haijun_ai_project_sharing_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • OwnedProjectsAccessRestored object

Access to owned projects was restored.

  • type: optional "owned_projects_access_restored"

default: owned_projects_access_restored

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • user_id: optional string or null

Tagged ID of the member whose access to their owned projects was restored, when known.

  • PaymentMethodUpdated object

The organization's default payment method was updated.

  • type: optional "payment_method_updated"

default: payment_method_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PendingShareCreated object

A pending share of a project or track was created for an email address that is not yet an organization member.

  • type: optional "pending_share_created"

default: pending_share_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • invitee_email: string

Email address the share was created for.

  • resource_id: string

Tagged ID of the resource being shared.

  • resource_type: string

The type of resource being shared.

  • role: string

The role that will be granted when the invitee joins the organization.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PendingShareRevoked object

A pending share of a project or track was revoked before the invitee joined the organization.

  • type: optional "pending_share_revoked"

default: pending_share_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • invitee_email: string

Email address the share had been created for.

  • resource_id: string

Tagged ID of the resource that was shared.

  • resource_type: string

The type of resource that was shared.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PhoneCodeSent object

User requested a phone verification code.

  • type: optional "phone_code_sent"

default: phone_code_sent

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PhoneCodeVerified object

User successfully verified their phone code.

  • type: optional "phone_code_verified"

default: phone_code_verified

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformAgentArchived object

An agent was archived on the API platform.

  • type: optional "platform_agent_archived"

default: platform_agent_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was archived, e.g. "agent_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentCreated object

An agent was created on the API platform.

  • type: optional "platform_agent_created"

default: platform_agent_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was created, e.g. "agent_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeleted object

An agent was deleted from the API platform.

  • type: optional "platform_agent_deleted"

default: platform_agent_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was deleted, e.g. "agent_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeploymentArchived object

An agent deployment was archived on the API platform.

  • type: optional "platform_agent_deployment_archived"

default: platform_agent_deployment_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deployment_id: string

The agent deployment that was archived, e.g. "depl_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeploymentCreated object

An agent deployment was created on the API platform.

  • type: optional "platform_agent_deployment_created"

default: platform_agent_deployment_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deployment_id: string

The agent deployment that was created, e.g. "depl_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeploymentDeleted object

An agent deployment was deleted from the API platform.

  • type: optional "platform_agent_deployment_deleted"

default: platform_agent_deployment_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deployment_id: string

The agent deployment that was deleted, e.g. "depl_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeploymentPaused object

An agent deployment was paused on the API platform.

  • type: optional "platform_agent_deployment_paused"

default: platform_agent_deployment_paused

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deployment_id: string

The agent deployment that was paused, e.g. "depl_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeploymentRunTriggered object

An agent deployment was run on demand on the API platform.

  • type: optional "platform_agent_deployment_run_triggered"

default: platform_agent_deployment_run_triggered

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deployment_id: string

The agent deployment that was run, e.g. "depl_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeploymentUnpaused object

An agent deployment was resumed on the API platform.

  • type: optional "platform_agent_deployment_unpaused"

default: platform_agent_deployment_unpaused

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deployment_id: string

The agent deployment that was resumed, e.g. "depl_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentDeploymentUpdated object

An agent deployment was updated on the API platform.

  • type: optional "platform_agent_deployment_updated"

default: platform_agent_deployment_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • deployment_id: string

The agent deployment that was updated, e.g. "depl_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionArchived object

An agent session was archived on the API platform.

  • type: optional "platform_agent_session_archived"

default: platform_agent_session_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The agent session that was archived, e.g. "session_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionCreated object

An agent session was created on the API platform.

  • type: optional "platform_agent_session_created"

default: platform_agent_session_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The agent session that was created, e.g. "session_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionDeleted object

An agent session was deleted from the API platform.

  • type: optional "platform_agent_session_deleted"

default: platform_agent_session_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The agent session that was deleted, e.g. "session_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionResourceAdded object

A resource was attached to an agent session.

  • type: optional "platform_agent_session_resource_added"

default: platform_agent_session_resource_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resource_id: string

The resource that was attached, e.g. "resource_01HX...".

  • session_id: string

The agent session the resource was attached to, e.g. "session_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionResourceDeleted object

A resource attached to an agent session was removed.

  • type: optional "platform_agent_session_resource_deleted"

default: platform_agent_session_resource_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resource_id: string

The resource that was removed, e.g. "resource_01HX...".

  • session_id: string

The agent session the resource belonged to, e.g. "session_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionResourceUpdated object

A resource attached to an agent session was updated.

  • type: optional "platform_agent_session_resource_updated"

default: platform_agent_session_resource_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resource_id: string

The resource that was updated, e.g. "resource_01HX...".

  • session_id: string

The agent session the resource belongs to, e.g. "session_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionThreadArchived object

A thread within an agent session was archived.

  • type: optional "platform_agent_session_thread_archived"

default: platform_agent_session_thread_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The agent session the thread belongs to, e.g. "session_01HX...".

  • thread_id: string

The thread that was archived, e.g. "thread_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentSessionUpdated object

An agent session was updated on the API platform.

  • type: optional "platform_agent_session_updated"

default: platform_agent_session_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • session_id: string

The agent session that was updated, e.g. "session_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAgentUpdated object

An agent was updated on the API platform.

  • type: optional "platform_agent_updated"

default: platform_agent_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • agent_id: string

The agent that was updated, e.g. "agent_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.

  • PlatformAPIKeyCreated object

An API key was created.

  • type: optional "platform_api_key_created"

default: platform_api_key_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • api_key_id: string

Tagged ID of the created API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • principal_id: optional string or null

For an identity-linked API key, the tagged ID of the user (e.g. "user_01HX...") or service account (e.g. "svac_01HX...") the key acts as. Absent for keys not linked to an identity.

  • principal_type: optional "service_account" or "unspecified" or "user" or null

For an identity-linked API key, the kind of identity the key acts as: "user" or "service_account". Absent for keys not linked to an identity.

  • "service_account"
  • "unspecified"
  • "user"
  • scope: optional Organization or Workspace or null

Where the API key belongs: one workspace ({"type": "workspace", "workspace_id": "wrkspc_..."}, with the workspace's ID even when it is the organization's default workspace), or the whole organization ({"type": "organization"}) for an identity-linked API key that has no workspace. May be absent on activities recorded before this field was introduced.

  • Organization object

The API key belongs to the whole organization and has no workspace.

  • type: optional "organization"

default: organization

  • Workspace object

The API key belongs to one workspace.

  • type: optional "workspace"

default: workspace

  • workspace_id: string

Tagged ID of the workspace the API key belongs to, including when that is the organization's default workspace.

  • PlatformAPIKeyUpdated object

An API key was updated.

  • type: optional "platform_api_key_updated"

default: platform_api_key_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • api_key_id: string

Tagged ID of the updated API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "name" or "status" or "unspecified" or "workspace"

The API key field that changed

  • "name"
  • "status"
  • "unspecified"
  • "workspace"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • PlatformAppAttestAuthentication object

An attested mobile device attempted to exchange an Apple App Attest assertion for Juglow API credentials.

  • type: optional "platform_app_attest_authentication"

default: platform_app_attest_authentication

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • event_data: optional object or null

Details of the authentication attempt.

  • external_client_id: optional string or null

The registered external client the device presented, e.g. "clid_01HXZ4J2N8K5P7R9T3V6W1Y4M0".

  • kid_hash: optional string or null

A truncated hash of the device's attested key identifier.

  • workspace_id: optional string or null

The tagged ID of the workspace the minted token is bound to.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • request_id: optional string or null

The Juglow API request identifier for correlation.

  • status: optional object or null

The outcome of the token exchange.

  • outcome: string

Whether the token exchange succeeded or was denied.

  • reason: optional string or null

A short reason code when the exchange did not succeed.

  • PlatformBillingUpgradedToPrepaid object

The organization's API billing was upgraded to the prepaid plan.

  • type: optional "platform_billing_upgraded_to_prepaid"

default: platform_billing_upgraded_to_prepaid

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • previous_billing_type: string

The organization's billing type before this upgrade, for example "api_evaluation".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformClearanceWorkspaceProgramRequestCleared object

A workspace's clearance program assignment was removed.

  • type: optional "platform_clearance_workspace_program_request_cleared"

default: platform_clearance_workspace_program_request_cleared

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • program_slug: string

The clearance program's identifier

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformClearanceWorkspaceProgramRequestSet object

A workspace's clearance program assignment was created or updated.

  • type: optional "platform_clearance_workspace_program_request_set"

default: platform_clearance_workspace_program_request_set

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • opt_decision: "opt_in" or "opt_out" or "unspecified"

Whether the workspace is opted in or out of the program

  • "opt_in"
  • "opt_out"
  • "unspecified"
  • program_slug: string

The clearance program's identifier

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformCostReportViewed object

The cost report was viewed.

  • type: optional "platform_cost_report_viewed"

default: platform_cost_report_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformDreamArchived object

A Dream (asynchronous memory-consolidation job) was archived.

  • type: optional "platform_dream_archived"

default: platform_dream_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • dream_id: string

Tagged dream ID, e.g. "drm_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the dream belongs to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace.

  • PlatformDreamCancelled object

A Dream (asynchronous memory-consolidation job) was cancelled before it completed.

  • type: optional "platform_dream_cancelled"

default: platform_dream_cancelled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • dream_id: string

Tagged dream ID, e.g. "drm_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the dream belongs to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace.

  • PlatformDreamCreated object

A Dream (asynchronous memory-consolidation job) was created.

  • type: optional "platform_dream_created"

default: platform_dream_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • dream_id: string

Tagged dream ID, e.g. "drm_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the dream belongs to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace.

  • PlatformFederatedAuthentication object

A federated workload identity attempted to exchange an OIDC token for Juglow API credentials.

  • type: optional "platform_federated_authentication"

default: platform_federated_authentication

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • event_data: optional object or null

Details of the authentication attempt.

  • federation_rule_id: optional string or null

The federation rule that matched the request, e.g. "fdrl_01HXZ4J2N8K5P7R9T3V6W1Y4M0".

  • issuer_id: optional string or null

The registered identity issuer for the request, e.g. "fdis_01HXZ4H5M3K8P1R7T9V2W6Y4N0".

  • oidc_token: optional object or null

Details of the presented OIDC token.

  • claims: optional map[unknown] or null

The verified claims from the presented OIDC token.

  • jti: optional string or null

The presented token's unique identifier (its jti claim).

  • requested_service_account_id: optional string or null

The service account the caller requested to authenticate as, e.g. "svac_01HXZ4...".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • request_id: optional string or null

The Juglow API request identifier for correlation, e.g. "req_01HXZ4K7M9P2QR5T8V6W3Y1N0B".

  • resources: optional array of object

The resources involved in the exchange.

  • type: string

The kind of resource involved in the exchange.

  • id: string

The identifier of the resource involved in the exchange.

  • status: optional object or null

The outcome of the token exchange.

  • outcome: string

Whether the token exchange succeeded or was denied.

  • detail: optional string or null

A human-readable explanation when the exchange did not succeed. May contain values copied verbatim from the presented token's header (e.g. kid, alg) and error text; treat as caller-supplied free text.

  • reason: optional string or null

A short reason code when the exchange did not succeed.

  • PlatformFederationIssuerArchived object

An OIDC federation issuer was archived.

  • type: optional "platform_federation_issuer_archived"

default: platform_federation_issuer_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • federation_issuer_id: string

Tagged ID of the archived issuer

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformFederationIssuerCreated object

An OIDC federation issuer was created, registering an external identity provider that federation rules can trust for workload authentication.

  • type: optional "platform_federation_issuer_created"

default: platform_federation_issuer_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • federation_issuer_id: string

Tagged ID of the created issuer, e.g. "fdis_..."

  • issuer_url: string

URL of the external OIDC identity provider that was registered

  • jwks_source: string

How the issuer's token-signing keys are obtained — typically "discovery" (the issuer's OIDC discovery document), "explicit_url" (a fixed JWKS URL), or "inline" (keys supplied directly at registration). An unrecognized source is recorded verbatim.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • discovery_base: optional string or null

Base URL for the OIDC discovery document, if a custom base was registered. Only present when jwks_source is "discovery".

  • jwks_url: optional string or null

The fixed URL where the issuer publishes its token-signing keys. Only present when jwks_source is "explicit_url".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformFederationIssuerUpdated object

An OIDC federation issuer was updated.

  • type: optional "platform_federation_issuer_updated"

default: platform_federation_issuer_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • federation_issuer_id: string

Tagged ID of the updated issuer

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "ca_cert_pem_sha256" or "check_jti" or "discovery_base" or 8 more

The OIDC federation issuer field that changed

  • "ca_cert_pem_sha256"
  • "check_jti"
  • "discovery_base"
  • "issuer_url"
  • "jwks_keys_sha256"
  • "jwks_polling_disabled_at"
  • "jwks_source"
  • "jwks_url"
  • "max_jwt_lifetime_seconds"
  • "name"
  • "unspecified"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • PlatformFederationRuleArchived object

An OIDC federation rule was archived.

  • type: optional "platform_federation_rule_archived"

default: platform_federation_rule_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • federation_rule_id: string

Tagged ID of the archived rule

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformFederationRuleCreated object

An OIDC federation rule was created, allowing tokens from a federation issuer to authenticate as a service account or user. Rules may additionally match on token claims or a condition expression, which are not included in this event.

  • type: optional "platform_federation_rule_created"

default: platform_federation_rule_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • applies_to_all_workspaces: boolean

Whether the rule applies to all workspaces in the organization.

  • federation_issuer_id: string

Tagged ID of the federation issuer the rule trusts

  • federation_rule_id: string

Tagged ID of the created rule, e.g. "fdrl_..."

  • oauth_scope: string

Space-separated OAuth scopes that tokens minted through the rule carry, e.g. "workspace:inference" or "org:admin".

  • target_type: string

What the rule authenticates as — typically "service_account" or "user". An unrecognized kind is recorded verbatim.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • match_audience: optional string or null

Token audience the rule matches, if one was set.

  • match_subject_prefix: optional string or null

Matcher for the token's sub claim, if one was set: exact match unless the value ends with , which makes it a prefix match. An empty value matches any subject. Example: "repo:acme/".

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • target_id: optional string or null

Tagged ID of the service account the rule authenticates as, e.g. "svac_...". Absent when target_type is "user": user rules identify the target by token-claim lookup rather than a fixed ID.

  • target_lookup_attr: optional string or null

Name of the rule attribute whose value resolves the target user. Only present when target_type is "user".

  • workspace_id: optional string or null

Tagged ID of the workspace the rule references, if one was set. May be set alongside applies_to_all_workspaces, which takes precedence: the rule then covers every workspace in the organization.

  • PlatformFederationRuleUpdated object

An OIDC federation rule was updated.

  • type: optional "platform_federation_rule_updated"

default: platform_federation_rule_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • federation_rule_id: string

Tagged ID of the updated rule

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "applies_to_all_workspaces" or "attributes" or "description" or 12 more

The OIDC federation rule field that changed

  • "applies_to_all_workspaces"
  • "attributes"
  • "description"
  • "match_audience"
  • "match_claims"
  • "match_condition"
  • "match_subject_prefix"
  • "name"
  • "oauth_scope"
  • "target_id"
  • "target_lookup_attr"
  • "target_type"
  • "token_lifetime_seconds"
  • "unspecified"
  • "workspace_id"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • PlatformFederationRuleWorkspaceAdded object

A federation rule was enabled for a workspace.

  • type: optional "platform_federation_rule_workspace_added"

default: platform_federation_rule_workspace_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • federation_rule_id: string

Tagged ID of the federation rule

  • workspace_id: string

Tagged ID of the workspace the rule was enabled for

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformFederationRuleWorkspaceRemoved object

A federation rule was disabled for a workspace.

  • type: optional "platform_federation_rule_workspace_removed"

default: platform_federation_rule_workspace_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • federation_rule_id: string

Tagged ID of the federation rule

  • workspace_id: string

Tagged ID of the workspace the rule was disabled for

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformFileContentDownloaded object

Activity logged when file content is downloaded via GET /v1/files/{file_id}/content.

  • type: optional "platform_file_content_downloaded"

default: platform_file_content_downloaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • file_id: string

The tagged ID of the downloaded file

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformFileDeleted object

Activity logged when a file is deleted via DELETE /v1/files/{file_id}.

  • type: optional "platform_file_deleted"

default: platform_file_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • file_id: string

The tagged ID of the deleted file

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformFileUploaded object

Activity logged when a file is uploaded via POST /v1/files.

  • type: optional "platform_file_uploaded"

default: platform_file_uploaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • file_id: string

The tagged ID of the uploaded file

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • session_id: optional string or null

The tagged session ID (agent-api only)

  • PlatformMemoryCreated object

An agent memory document was created.

  • type: optional "platform_memory_created"

default: platform_memory_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_id: string

Tagged memory ID, e.g. "mem_01HX...".

  • memory_store_id: string

Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • memory_version_id: optional string or null

Tagged ID of the memory version produced by this change, e.g. "memver_01HX...". Links this event to the version history.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformMemoryDeleted object

An agent memory document was deleted.

  • type: optional "platform_memory_deleted"

default: platform_memory_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_id: string

Tagged memory ID, e.g. "mem_01HX...".

  • memory_store_id: string

Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • memory_version_id: optional string or null

Tagged ID of the memory version produced by this change — the deletion tombstone, e.g. "memver_01HX...". Links this event to the version history.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformMemoryStoreArchived object

An agent memory store was archived. Archived stores reject new memory writes and cannot be attached to new sessions; deletion and redaction remain permitted for privacy scrubbing.

  • type: optional "platform_memory_store_archived"

default: platform_memory_store_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_store_id: string

Tagged memory store ID, e.g. "memstore_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformMemoryStoreCreated object

An agent memory store was created.

  • type: optional "platform_memory_store_created"

default: platform_memory_store_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_store_id: string

Tagged memory store ID, e.g. "memstore_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformMemoryStoreDeleted object

An agent memory store was deleted. Memory content removal may complete asynchronously for very large stores.

  • type: optional "platform_memory_store_deleted"

default: platform_memory_store_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_store_id: string

Tagged memory store ID, e.g. "memstore_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformMemoryStoreUpdated object

An agent memory store's name, description, or metadata was updated.

  • type: optional "platform_memory_store_updated"

default: platform_memory_store_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_store_id: string

Tagged memory store ID, e.g. "memstore_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformMemoryUpdated object

An agent memory document's content or path was updated.

  • type: optional "platform_memory_updated"

default: platform_memory_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_id: string

Tagged memory ID, e.g. "mem_01HX...".

  • memory_store_id: string

Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • memory_version_id: optional string or null

Tagged ID of the memory version produced by this change, e.g. "memver_01HX...". Links this event to the version history.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformMemoryVersionRedacted object

A historical version of an agent memory document was redacted. Redaction scrubs the stored content of a specific version while preserving the version's existence in the history.

  • type: optional "platform_memory_version_redacted"

default: platform_memory_version_redacted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • memory_id: string

Tagged ID of the memory the version belongs to, e.g. "mem_01HX...".

  • memory_store_id: string

Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".

  • memory_version_id: string

Tagged memory version ID, e.g. "memver_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.

  • PlatformOAuthAppCreated object

An OAuth app was created.

  • type: optional "platform_oauth_app_created"

default: platform_oauth_app_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • oauth_app_id: string

Tagged ID of the created app

  • workspace_id: string

Tagged ID of the workspace the app is scoped to

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformOAuthAppRevoked object

An OAuth app was revoked.

  • type: optional "platform_oauth_app_revoked"

default: platform_oauth_app_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • oauth_app_id: string

Tagged ID of the revoked app

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformOAuthAppUpdated object

An OAuth app was updated.

  • type: optional "platform_oauth_app_updated"

default: platform_oauth_app_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • oauth_app_id: string

Tagged ID of the updated app

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "apple_ios_attestation_environment" or "apple_ios_bundles" or "name" or 2 more

The OAuth app field that changed

  • "apple_ios_attestation_environment"
  • "apple_ios_bundles"
  • "name"
  • "status"
  • "unspecified"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • PlatformPluginDirectorySubmissionCreated object

A plugin directory submission was created on the API platform. A plugin directory submission is a request to list a plugin in the public plugin directory.

  • type: optional "platform_plugin_directory_submission_created"

default: platform_plugin_directory_submission_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • plugin_name: string

The name of the plugin being submitted.

  • submission_id: string

The submission that was created, e.g. "psub_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformPluginDirectorySubmissionDeleted object

A plugin directory submission was deleted on the API platform.

  • type: optional "platform_plugin_directory_submission_deleted"

default: platform_plugin_directory_submission_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • submission_id: string

The submission that was deleted, e.g. "psub_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformPluginDirectorySubmissionUpdated object

A plugin directory submission was updated on the API platform.

  • type: optional "platform_plugin_directory_submission_updated"

default: platform_plugin_directory_submission_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • status: string

The submission's status after the update.

  • submission_id: string

The submission that was updated, e.g. "psub_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformServiceAccountArchived object

A service account was archived.

  • type: optional "platform_service_account_archived"

default: platform_service_account_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_account_id: string

Tagged ID of the archived service account

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformServiceAccountCreated object

A service account was created.

  • type: optional "platform_service_account_created"

default: platform_service_account_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • organization_role: string

Organization role the service account was created with — typically "admin" or "developer". A role this service does not recognize is recorded verbatim.

  • service_account_id: string

Tagged ID of the created service account, e.g. "svac_..."

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformServiceAccountUpdated object

A service account was updated.

  • type: optional "platform_service_account_updated"

default: platform_service_account_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_account_id: string

Tagged ID of the updated service account

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "description" or "organization_role" or "unspecified"

The service account field that changed

  • "description"
  • "organization_role"
  • "unspecified"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • PlatformServiceAccountWorkspaceMemberAdded object

A service account was added as a member of a workspace.

  • type: optional "platform_service_account_workspace_member_added"

default: platform_service_account_workspace_member_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_account_id: string

Tagged ID of the service account

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_role: optional string or null

Role the service account was given in the workspace, for example workspace_developer.

  • PlatformServiceAccountWorkspaceMemberRemoved object

A service account was removed from a workspace.

  • type: optional "platform_service_account_workspace_member_removed"

default: platform_service_account_workspace_member_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_account_id: string

Tagged ID of the service account

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformServiceAccountWorkspaceMemberUpdated object

A service account's workspace membership role was updated.

  • type: optional "platform_service_account_workspace_member_updated"

default: platform_service_account_workspace_member_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_account_id: string

Tagged ID of the service account

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "unspecified" or "workspace_role"

The service account's workspace membership field that changed

  • "unspecified"
  • "workspace_role"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • PlatformSigningKeyCreated object

Activity logged when a new request-signing key is registered for the org.

  • type: optional "platform_signing_key_created"

default: platform_signing_key_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • algorithm: string

The signing algorithm (e.g. ecdsa-p256-sha256)

  • key_backing_type: string

The backing type of the key (IN_MEMORY or CLOUD_KMS)

  • signing_key_id: string

The tagged ID of the created signing key

  • status: string

The initial status of the key (ACTIVE or PENDING)

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSigningKeyDeleted object

Activity logged when a signing key is permanently deleted.

  • type: optional "platform_signing_key_deleted"

default: platform_signing_key_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • algorithm: string

The algorithm of the deleted key

  • key_backing_type: string

The backing type of the deleted key (IN_MEMORY or CLOUD_KMS)

  • key_name: string

The name of the deleted key

  • signing_key_id: string

The tagged ID of the deleted signing key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSigningKeyRotated object

Activity logged when an in-memory signing key is rotated.

  • type: optional "platform_signing_key_rotated"

default: platform_signing_key_rotated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • algorithm: string

The algorithm of the new key

  • key_group_identifier: string

The key group identifier linking old and new keys

  • new_signing_key_id: string

The tagged ID of the newly created key

  • old_signing_key_id: string

The tagged ID of the expired old key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSkillVersionContentDownloaded object

The content of a track version was downloaded through the Tracks API.

  • type: optional "platform_skill_version_content_downloaded"

default: platform_skill_version_content_downloaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • skill_id: string

The tagged ID of the track

  • version: string

The version of the track whose content was downloaded

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSkillVersionCreated object

Activity logged when a track version is created via POST /v1/tracks/{skill_id}/versions.

  • type: optional "platform_skill_version_created"

default: platform_skill_version_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • skill_id: string

The tagged ID of the track

  • version: string

The version number of the created version

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSkillVersionDeleted object

Activity logged when a track version is deleted via DELETE /v1/tracks/{skill_id}/versions/{version}.

  • type: optional "platform_skill_version_deleted"

default: platform_skill_version_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • skill_id: string

The tagged ID of the track

  • version: string

The version number of the deleted version

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSpendLimitAlertEmailsUpdated object

Spend limit alert email addresses and role targets were updated for an org.

  • type: optional "platform_spend_limit_alert_emails_updated"

default: platform_spend_limit_alert_emails_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • alert_emails: optional array of string or null

Updated list of alert email addresses.

  • alerted_roles: optional array of string or null

Updated list of alerted roles.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSpendLimitCreated object

An org-level fixed-dollar spend limit was created.

  • type: optional "platform_spend_limit_created"

default: platform_spend_limit_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • limit_action: optional string or null

The action taken when the limit is reached (notify_only or notify_and_pause).

  • limit_usd: optional number or null

The spend limit threshold in USD cents.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformSpendLimitDeleted object

An org-level spend limit was removed.

  • type: optional "platform_spend_limit_deleted"

default: platform_spend_limit_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

UUID of the deleted spend limit.

  • PlatformSpendLimitUpdated object

An org-level spend limit snooze/ignore state was changed.

  • type: optional "platform_spend_limit_updated"

default: platform_spend_limit_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • ignore: optional boolean or null

Whether the limit is being snoozed (ignored).

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

UUID of the spend limit.

  • PlatformUsageReportHaijunCodeViewed object

The Haijun Code usage report was viewed.

  • type: optional "platform_usage_report_haijun_code_viewed"

default: platform_usage_report_haijun_code_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformUsageReportMessagesViewed object

The messages usage report was viewed.

  • type: optional "platform_usage_report_messages_viewed"

default: platform_usage_report_messages_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceArchived object

A workspace was archived.

  • type: optional "platform_workspace_archived"

default: platform_workspace_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • workspace_id: string

Tagged ID of the archived workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceCreated object

A workspace was created.

  • type: optional "platform_workspace_created"

default: platform_workspace_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • workspace_id: string

Tagged ID of the created workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceInferenceDataRetentionDisabled object

The zero data retention override was disabled for a workspace.

  • type: optional "platform_workspace_inference_data_retention_disabled"

default: platform_workspace_inference_data_retention_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Override state immediately before this change

  • PlatformWorkspaceInferenceDataRetentionEnabled object

The zero data retention override was enabled for a workspace.

  • type: optional "platform_workspace_inference_data_retention_enabled"

default: platform_workspace_inference_data_retention_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_value: optional boolean or null

Override state immediately before this change

  • PlatformWorkspaceMemberAdded object

A member was added to a workspace.

  • type: optional "platform_workspace_member_added"

default: platform_workspace_member_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string

Tagged ID of the added member

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceMemberRemoved object

A member was removed from a workspace.

  • type: optional "platform_workspace_member_removed"

default: platform_workspace_member_removed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string

Tagged ID of the removed member

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceMemberUpdated object

A workspace member was updated.

  • type: optional "platform_workspace_member_updated"

default: platform_workspace_member_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string

Tagged ID of the updated member

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "unspecified" or "workspace_role"

The workspace member field that changed

  • "unspecified"
  • "workspace_role"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • PlatformWorkspaceMemberViewed object

A workspace member was viewed.

  • type: optional "platform_workspace_member_viewed"

default: platform_workspace_member_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string

Tagged ID of the viewed member

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceMembersListed object

Workspace members were listed.

  • type: optional "platform_workspace_members_listed"

default: platform_workspace_members_listed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceRateLimitDeleted object

A workspace rate limit was deleted.

  • type: optional "platform_workspace_rate_limit_deleted"

default: platform_workspace_rate_limit_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • limiter_type: string

Type of rate limiter

  • model_group: string

Model group the rate limit applied to

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceRateLimitUpdated object

A workspace rate limit was created or updated.

  • type: optional "platform_workspace_rate_limit_updated"

default: platform_workspace_rate_limit_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • limiter_type: string

Type of rate limiter

  • model_group: string

Model group the rate limit applies to

  • value: number

New rate limit value

  • workspace_id: string

Tagged ID of the workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PlatformWorkspaceUpdated object

A workspace was updated.

  • type: optional "platform_workspace_updated"

default: platform_workspace_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • workspace_id: string

Tagged ID of the updated workspace

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "allowed_inference_geos" or "default_inference_geo" or "display_color" or 4 more

The workspace field that changed

  • "allowed_inference_geos"
  • "default_inference_geo"
  • "display_color"
  • "external_key_config_id"
  • "inference_data_retention"
  • "name"
  • "unspecified"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • HaijunPluginCreated object

Plugin was created.

  • type: optional "haijun_plugin_created"

default: haijun_plugin_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_id: optional string or null
  • plugin_name: optional string or null
  • HaijunPluginDeleted object

Plugin was deleted.

  • type: optional "haijun_plugin_deleted"

default: haijun_plugin_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_id: optional string or null
  • plugin_name: optional string or null
  • HaijunPluginDisabled object

User disabled a plugin for their account.

  • type: optional "haijun_plugin_disabled"

default: haijun_plugin_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • marketplace_id: optional string or null

Identifier of the marketplace the plugin was installed from.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_id: optional string or null

Identifier of the plugin that was disabled.

  • plugin_name: optional string or null

Name of the plugin that was disabled.

  • HaijunPluginEnabled object

User enabled a plugin for their account.

  • type: optional "haijun_plugin_enabled"

default: haijun_plugin_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • marketplace_id: optional string or null

Identifier of the marketplace the plugin was installed from.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_id: optional string or null

Identifier of the plugin that was enabled.

  • plugin_name: optional string or null

Name of the plugin that was enabled.

  • PluginInstallationPreferenceUpdated object

An org admin changed the installation preference for a plugin.

  • type: optional "plugin_installation_preference_updated"

default: plugin_installation_preference_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • marketplace_id: string

Marketplace ID

  • plugin_name: string

Plugin name

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • action: optional string or null

Action taken (e.g. 'deleted' for clearing an override)

  • created_at: optional string

When this activity occurred.

format: date-time

  • group_id: optional string or null

Tagged group ID for group-level overrides (null for org-level)

  • group_name: optional string or null

Group name for group-level overrides

  • installation_preference: optional string or null

New installation preference value (set only when action is an update; null for delete actions)

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_installation_preference: optional string or null

Installation preference value before this change, at the same level (organization or group); absent when none was set before

  • HaijunPluginReplaced object

Plugin was replaced.

  • type: optional "haijun_plugin_replaced"

default: haijun_plugin_replaced

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_id: optional string or null
  • plugin_name: optional string or null
  • HaijunPluginSecurityScanCompleted object

A security scan of a plugin completed and produced a verdict.

  • type: optional "haijun_plugin_security_scan_completed"

default: haijun_plugin_security_scan_completed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_id: string

Identifier of the security scan.

  • verdict: "fail" or "pass" or "unknown" or 2 more

Verdict the scan produced.

  • "fail"
  • "pass"
  • "unknown"
  • "unspecified"
  • "warn"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_id: optional string or null

Identifier of the plugin that was scanned.

  • plugin_name: optional string or null

Name of the plugin that was scanned.

  • plugin_version: optional string or null

Version of the plugin that was scanned.

  • HaijunPluginUpdated object

Plugin was updated.

  • type: optional "haijun_plugin_updated"

default: haijun_plugin_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plugin_id: optional string or null
  • plugin_name: optional string or null
  • PrepaidAutoRechargeDisabled object

Auto-recharge was disabled for API prepaid org.

  • type: optional "prepaid_auto_recharge_disabled"

default: prepaid_auto_recharge_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PrepaidAutoRechargeUpdated object

Auto-recharge settings were updated for API prepaid org.

  • type: optional "prepaid_auto_recharge_updated"

default: prepaid_auto_recharge_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • target_amount: optional number or null

Target recharge amount in minor units.

  • threshold_amount: optional number or null

Threshold amount to trigger recharge in minor units.

  • PrepaidExtraUsageAutoReloadDisabled object

Prepaid usage credit auto-reload was disabled.

  • type: optional "prepaid_extra_usage_auto_reload_disabled"

default: prepaid_extra_usage_auto_reload_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PrepaidExtraUsageAutoReloadEnabled object

Prepaid usage credit auto-reload was enabled.

  • type: optional "prepaid_extra_usage_auto_reload_enabled"

default: prepaid_extra_usage_auto_reload_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PrepaidExtraUsageAutoReloadSettingsUpdated object

Prepaid usage credit auto-reload settings were updated.

  • type: optional "prepaid_extra_usage_auto_reload_settings_updated"

default: prepaid_extra_usage_auto_reload_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • PrimaryOwnerTransferred object

Primary owner role was transferred to another org member.

  • type: optional "primary_owner_transferred"

default: primary_owner_transferred

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • new_owner_id: string

Tagged ID of the member who became the primary owner.

  • previous_owner_id: string

Tagged ID of the member who was the primary owner before the transfer.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectArchived object

A Haijun project was archived.

  • type: optional "haijun_project_archived"

default: haijun_project_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project that was archived, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectCreated object

A Haijun project was created.

  • type: optional "haijun_project_created"

default: haijun_project_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project that was created, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDeleted object

A Haijun project was deleted.

  • type: optional "haijun_project_deleted"

default: haijun_project_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project that was deleted, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDocumentAccessFailed object

An attempt to access a document in a Haijun project failed.

  • type: optional "haijun_project_document_access_failed"

default: haijun_project_document_access_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project the request targeted, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_document_id: optional string or null

Tagged ID of the document the request tried to access, e.g. "haijun_proj_doc_01HX...". Absent when the request did not carry a well-formed document identifier.

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the document, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDocumentBulkDeletionAuditTruncated object

A bulk request to delete documents from a Haijun project failed with more documents requested than were individually recorded in the audit log.

  • type: optional "haijun_project_document_bulk_deletion_audit_truncated"

default: haijun_project_document_bulk_deletion_audit_truncated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • audited_count: number

Number of documents that received an individual audit record.

  • haijun_project_id: string

Tagged ID of the project the bulk deletion targeted, e.g. "haijun_proj_01HX...".

  • requested_count: number

Total number of documents the request asked to delete.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDocumentDeleted object

A document was deleted from a Haijun project.

  • type: optional "haijun_project_document_deleted"

default: haijun_project_document_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_document_id: string

Tagged ID of the document that was deleted, e.g. "haijun_proj_doc_01HX...".

  • haijun_project_id: string

Tagged ID of the project the document was deleted from, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the deleted document, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDocumentDeletionFailed object

A request to delete a document from a Haijun project failed.

  • type: optional "haijun_project_document_deletion_failed"

default: haijun_project_document_deletion_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project the deletion targeted, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_project_document_id: optional string or null

Tagged ID of the document the deletion targeted, e.g. "haijun_proj_doc_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the document, when known.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDocumentUpdated object

The content of a document in a Haijun project was replaced in place.

  • type: optional "haijun_project_document_updated"

default: haijun_project_document_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_document_id: string

Tagged ID of the document whose content was replaced, e.g. "haijun_proj_doc_01HX...".

  • haijun_project_id: string

Tagged ID of the project containing the document, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the updated document.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDocumentUploaded object

A document was uploaded to a Haijun project.

  • type: optional "haijun_project_document_uploaded"

default: haijun_project_document_uploaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_document_id: string

Tagged ID of the document that was uploaded, e.g. "haijun_proj_doc_01HX...".

  • haijun_project_id: string

Tagged ID of the project the document was uploaded to, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the uploaded document.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectDocumentViewed object

A document in a Haijun project was viewed.

  • type: optional "haijun_project_document_viewed"

default: haijun_project_document_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_document_id: string

Tagged ID of the document that was viewed, e.g. "haijun_proj_doc_01HX...".

  • haijun_project_id: string

Tagged ID of the project containing the document, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the viewed document.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectFileAccessFailed object

An attempt to access a file in a Haijun project failed.

  • type: optional "haijun_project_file_access_failed"

default: haijun_project_file_access_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_file_id: string

Tagged ID of the file the request tried to access, e.g. "haijun_file_01HX...".

  • haijun_project_id: string

Tagged ID of the project the request targeted, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectFileBulkDeletionAuditTruncated object

A bulk request to delete files from a Haijun project failed with more files requested than were individually recorded in the audit log.

  • type: optional "haijun_project_file_bulk_deletion_audit_truncated"

default: haijun_project_file_bulk_deletion_audit_truncated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • audited_count: number

Number of files that received an individual audit record.

  • haijun_project_id: string

Tagged ID of the project the bulk deletion targeted, e.g. "haijun_proj_01HX...".

  • requested_count: number

Total number of files the request asked to delete.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectFileDeleted object

A file was deleted from a Haijun project.

  • type: optional "haijun_project_file_deleted"

default: haijun_project_file_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_file_id: string

Tagged ID of the file that was deleted, e.g. "haijun_file_01HX...".

  • haijun_project_id: string

Tagged ID of the project the file was deleted from, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectFileDeletionFailed object

A request to delete a file from a Haijun project failed.

  • type: optional "haijun_project_file_deletion_failed"

default: haijun_project_file_deletion_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project the deletion targeted, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • haijun_file_id: optional string or null

Tagged ID of the file that was not deleted, e.g. "haijun_file_01HX...".

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectFileUploaded object

A file was uploaded to a Haijun project.

  • type: optional "haijun_project_file_uploaded"

default: haijun_project_file_uploaded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_file_id: string

Tagged ID of the file that was uploaded, e.g. "haijun_file_01HX...".

  • haijun_project_id: string

Tagged ID of the project the file was uploaded to, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • filename: optional string or null

Name of the uploaded file.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectReported object

A Haijun project was reported.

  • type: optional "haijun_project_reported"

default: haijun_project_reported

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project that was reported, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectSharingUpdated object

A Haijun project's sharing settings were updated.

  • type: optional "haijun_project_sharing_updated"

default: haijun_project_sharing_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • audience: array of Public or Organization

Sharing audience for the project. If empty, it's only visible to the creating user.

  • Public object

Sharing audience: public.

  • type: optional "public"

default: public

  • Organization object

Sharing audience: the project is visible to members of the owning organization.

  • type: optional "organization"

default: organization

  • haijun_project_id: string

The project's identifier, e.g. "haijun_proj_01Ab...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunProjectViewed object

A Haijun project was viewed.

  • type: optional "haijun_project_viewed"

default: haijun_project_viewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • haijun_project_id: string

Tagged ID of the project that was viewed, e.g. "haijun_proj_01HX...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • preview_only: optional boolean or null

Whether only the project's summary metadata was viewed rather than the full project.

  • HaijunPubsecIdentityConfigured object

SAML IdP configuration updated for a public sector organization.

  • type: optional "haijun_pubsec_identity_configured"

default: haijun_pubsec_identity_configured

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • idp_saml_config_updated: boolean
  • magic_link_toggled: boolean
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • magic_link_enabled: optional boolean or null
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRoleAssigned object

Admin assigned an RBAC custom role to a principal.

  • type: optional "rbac_role_assigned"

default: rbac_role_assigned

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • principal_id: string

Tagged ID of the principal

  • principal_type: string

Type of principal: account, group, or service_account

  • role_id: string

Tagged ID of the role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRoleCreated object

Admin created an RBAC custom role.

  • type: optional "rbac_role_created"

default: rbac_role_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • role_id: string

Tagged ID of the created role

  • role_name: string

Name of the created role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRoleDeleted object

Admin deleted an RBAC custom role.

  • type: optional "rbac_role_deleted"

default: rbac_role_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • role_id: string

Tagged ID of the deleted role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRoleGrantUpdated object

Admin requested a capability grant for an RBAC custom role, or removed it.

Records the admin's change to the role. Whether the grant is currently in effect on the role is reported separately.

  • type: optional "rbac_role_grant_updated"

default: rbac_role_grant_updated

  • action: "removed" or "requested" or "unspecified"

Whether the grant was requested for the role or removed from it

  • "removed"
  • "requested"
  • "unspecified"
  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • grant_type: string

The type of capability grant

  • role_id: string

Tagged ID of the role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRolePermissionAdded object

Admin added a permission to an RBAC custom role.

Emitted once per requested permission, including permissions the role already had, so a retried request still produces a complete audit record.

  • type: optional "rbac_role_permission_added"

default: rbac_role_permission_added

  • action: string

Action permitted on the resource

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resource_id: string

ID of the resource

  • resource_type: string

Type of resource the permission applies to

  • role_id: string

Tagged ID of the role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRolePermissionRemoved object

Admin removed a permission from an RBAC custom role.

Emitted once per requested permission, including permissions the role already lacked, so a retried request still produces a complete audit record.

  • type: optional "rbac_role_permission_removed"

default: rbac_role_permission_removed

  • action: string

Action that was permitted on the resource

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • resource_id: string

ID of the resource

  • resource_type: string

Type of resource the permission applied to

  • role_id: string

Tagged ID of the role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRoleUnassigned object

Admin unassigned an RBAC custom role from a principal.

  • type: optional "rbac_role_unassigned"

default: rbac_role_unassigned

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • principal_id: string

Tagged ID of the principal

  • principal_type: string

Type of principal: account, group, or service_account

  • role_id: string

Tagged ID of the role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RbacRoleUpdated object

Admin updated an RBAC custom role.

  • type: optional "rbac_role_updated"

default: rbac_role_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • role_id: string

Tagged ID of the updated role

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • RoleAssignmentGranted object

Role assignment was granted.

  • type: optional "role_assignment_granted"

default: role_assignment_granted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • resource_id: optional string or null

ID of the resource the role is on.

  • resource_type: optional string or null

What kind of resource the role is on, for example "chat_project", "track", or "plugin".

  • role: optional string or null

The role that was granted, for example "track:viewer" or "plugin:viewer".

  • target_email: optional string or null

Email address of the person who received the role when they are an invitee identified by email address or an account outside the organization; absent or null for members and groups.

  • target_id: optional string or null

ID of the grantee: a user ID for a member or for an account outside the organization, a group ID for a group, the organization ID for an organization-wide grant, or an opaque "email:" key for an invitee identified only by email address.

  • target_type: optional string or null

What kind of grantee received the role, for example "organization_member", "group", "organization", "account" (an account outside the organization), or "email" (an invitee identified by email address).

  • RoleAssignmentRevoked object

Role assignment was revoked.

  • type: optional "role_assignment_revoked"

default: role_assignment_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • resource_id: optional string or null

ID of the resource the role was on.

  • resource_type: optional string or null

What kind of resource the role was on, for example "chat_project", "track", or "plugin".

  • role: optional string or null

The role that was revoked, for example "track:viewer" or "plugin:viewer".

  • target_email: optional string or null

Email address of the person who held the role when they are an invitee identified by email address or an account outside the organization; absent or null for members and groups.

  • target_id: optional string or null

ID of the grantee that held the role: a user ID for a member or for an account outside the organization, a group ID for a group, the organization ID for an organization-wide grant, or an opaque "email:" key for an invitee identified only by email address.

  • target_type: optional string or null

What kind of grantee held the role, for example "organization_member", "group", "organization", "account" (an account outside the organization), or "email" (an invitee identified by email address).

  • SSOLoginFailed object

An SSO sign-in attempt failed.

  • type: optional "sso_login_failed"

default: sso_login_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SSOLoginInitiated object

A user started an SSO sign-in flow.

  • type: optional "sso_login_initiated"

default: sso_login_initiated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SSOLoginSucceeded object

A user successfully signed in with SSO.

  • type: optional "sso_login_succeeded"

default: sso_login_succeeded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • auth_method: optional "sso" or "unspecified" or null

The method the user used to authenticate. May be absent on activities recorded before this field was introduced.

  • "sso"
  • "unspecified"
  • created_at: optional string

When this activity occurred.

format: date-time

  • mfa_method: optional "not_used" or "unspecified" or null

The second authentication factor performed during this login, if any. null when the second-factor status is not recorded on this event — for example, when authentication was delegated to an external identity provider and any second factor is not visible to Juglow, or when this event is one step of a multistep login whose MFA is reported on another activity. May be absent on activities recorded before this field was introduced.

  • "not_used"
  • "unspecified"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SSOSecondFactorMagicLink object

SSO second factor magic link was used.

  • type: optional "sso_second_factor_magic_link"

default: sso_second_factor_magic_link

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ScimUserCreated object

A SCIM user was provisioned.

  • type: optional "scim_user_created"

default: scim_user_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ScimUserDeleted object

A SCIM user was deleted.

  • type: optional "scim_user_deleted"

default: scim_user_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ScimUserUpdated object

A SCIM user was updated.

  • type: optional "scim_user_updated"

default: scim_user_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ScopedAPIKeyDeleted object

A scoped API key was deleted.

  • type: optional "scoped_api_key_deleted"

default: scoped_api_key_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • api_key_id: string

Tagged ID of the deleted scoped API key

  • api_key_name: string

Name of the deleted scoped API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scopes: optional array of string

Scopes the deleted key had

  • ScopedAPIKeyUpdated object

A scoped API key was renamed or its activation state changed.

  • type: optional "scoped_api_key_updated"

default: scoped_api_key_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • api_key_id: string

Tagged ID of the updated scoped API key

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • updates: optional array of object

The field-level changes applied in this update

  • type: "activation_state" or "name" or "unspecified"

The scoped API key field that changed

  • "activation_state"
  • "name"
  • "unspecified"
  • current_value: string

Field value immediately after this change

  • previous_value: string

Field value immediately before this change

  • SeatTierChangesCancelled object

Scheduled seat tier downgrades were cancelled.

  • type: optional "seat_tier_changes_cancelled"

default: seat_tier_changes_cancelled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SeatTiersPurchased object

Seat tiers were purchased or upgraded on a subscription.

  • type: optional "seat_tiers_purchased"

default: seat_tiers_purchased

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • item_allocations: optional map[number] or null

Desired seat tier allocations (item type to quantity).

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ServiceCreated object

Activity logged when an org service is explicitly created.

  • type: optional "service_created"

default: service_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_name: string

The org service name (e.g., 'external:my-service')

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ServiceDeleted object

Activity logged when an org service is deleted.

  • type: optional "service_deleted"

default: service_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_name: string

The org service name (e.g., 'external:my-service')

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • ServiceKeyCreated object

Activity logged when a new org service key is created.

  • type: optional "service_key_created"

default: service_key_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • is_service_created: boolean

Whether the org service was implicitly created in this request

  • key_name: string

The human-readable name of the key

  • service_name: string

The service name this key belongs to

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scopes: optional array of string

The scopes granted to this service key

  • service_key_id: optional string or null

The ID of the created service key

  • ServiceKeyRevoked object

Activity logged when an org service key is revoked.

  • type: optional "service_key_revoked"

default: service_key_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • service_key_id: string

The tagged ID of the revoked service key

  • service_name: string

The service name this key belongs to

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SessionRevoked object

User revoked a specific session.

  • type: optional "session_revoked"

default: session_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SessionShareAccessed object

Session share was accessed.

  • type: optional "session_share_accessed"

default: session_share_accessed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • share_id: optional string or null
  • SessionShareCreated object

Session share was created.

  • type: optional "session_share_created"

default: session_share_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • access_level: optional string or null

Access level granted for the share.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • share_id: optional string or null
  • SessionShareRevoked object

Session share was revoked.

  • type: optional "session_share_revoked"

default: session_share_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • reason: optional string or null

Why the share was revoked.

  • share_id: optional string or null
  • HaijunSkillCreated object

Track was created.

  • type: optional "haijun_skill_created"

default: haijun_skill_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • owner_user_id: optional string or null

The member who owns the track; unset for an organization-owned track.

  • scope: optional "organization" or "personal" or "unspecified" or null

Whether the track is the member's own or the organization's.

  • "organization"
  • "personal"
  • "unspecified"
  • skill_id: optional string or null
  • skill_name: optional string or null
  • skill_version: optional string or null

Version of the track that was created.

  • HaijunSkillDeleted object

Track was deleted.

  • type: optional "haijun_skill_deleted"

default: haijun_skill_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • deleted_version_ids: optional array of string
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • owner_user_id: optional string or null

The member who owns the track; unset for an organization-owned track.

  • scope: optional "organization" or "personal" or "unspecified" or null

Whether the track is the member's own or the organization's.

  • "organization"
  • "personal"
  • "unspecified"
  • skill_id: optional string or null
  • skill_name: optional string or null
  • skill_version: optional string or null

Latest version of the track when it was deleted.

  • versions_deleted: optional number or null

Set when the deletion removed the track's versions in the same request (the public API's cascading track delete): one consolidated record of what went with the track, reconcilable against earlier version-created records, rather than one version-deleted activity per row. versions_deleted is the exact count; deleted_version_ids lists at most the newest 1000 (truncated when versions_deleted exceeds its length).

  • HaijunSkillDisabled object

User disabled a track for their account.

  • type: optional "haijun_skill_disabled"

default: haijun_skill_disabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • skill_id: optional string or null
  • skill_name: optional string or null
  • HaijunSkillEnabled object

User enabled a track for their account.

  • type: optional "haijun_skill_enabled"

default: haijun_skill_enabled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • skill_id: optional string or null
  • skill_name: optional string or null
  • HaijunSkillReplaced object

Track was replaced.

  • type: optional "haijun_skill_replaced"

default: haijun_skill_replaced

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • owner_user_id: optional string or null

The member who owns the track; unset for an organization-owned track.

  • scope: optional "organization" or "personal" or "unspecified" or null

Whether the track is the member's own or the organization's.

  • "organization"
  • "personal"
  • "unspecified"
  • skill_id: optional string or null
  • skill_name: optional string or null
  • skill_version: optional string or null

Version of the track after it was replaced.

  • HaijunSkillSecurityScanCompleted object

A security scan of a track completed and produced a verdict.

  • type: optional "haijun_skill_security_scan_completed"

default: haijun_skill_security_scan_completed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • scan_id: string

Identifier of the security scan.

  • verdict: "fail" or "pass" or "unknown" or 2 more

Verdict the scan produced.

  • "fail"
  • "pass"
  • "unknown"
  • "unspecified"
  • "warn"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • skill_id: optional string or null

Identifier of the track that was scanned.

  • skill_name: optional string or null

Name of the track that was scanned.

  • skill_version: optional string or null

Version of the track that was scanned.

  • SlackWorkspaceClaimRevoked object

A Slack workspace or Enterprise Grid organization was disconnected from the organization for Haijun in Slack.

  • type: optional "slack_workspace_claim_revoked"

default: slack_workspace_claim_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • slack_team_id: string

Claim subject: a Slack team id for scope 'workspace', or an Enterprise Grid org id for scope 'enterprise_grid'. Use the scope field to tell which — never the value's prefix (legacy workspaces exist with E-prefixed team ids)

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scope: optional string or null

Blast radius of the revocation: 'workspace' for one Slack workspace, 'enterprise_grid' for every workspace in a Slack Enterprise Grid organization

  • SlackWorkspaceClaimed object

A Slack workspace or Enterprise Grid organization was connected to the organization for Haijun in Slack.

  • type: optional "slack_workspace_claimed"

default: slack_workspace_claimed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • slack_team_id: string

Claim subject: a Slack team id for scope 'workspace', or an Enterprise Grid org id for scope 'enterprise_grid'. Use the scope field to tell which — never the value's prefix (legacy workspaces exist with E-prefixed team ids)

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • scope: optional string or null

Blast radius of the claim: 'workspace' for one Slack workspace, 'enterprise_grid' for every workspace in a Slack Enterprise Grid organization

  • SocialLoginSucceeded object

A user successfully signed in with a social identity provider (Google, Apple, or Microsoft).

  • type: optional "social_login_succeeded"

default: social_login_succeeded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • provider: "apple" or "google" or "microsoft" or "unspecified"

The social identity provider the user signed in with: "google", "apple", or "microsoft".

  • "apple"
  • "google"
  • "microsoft"
  • "unspecified"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • auth_method: optional "social" or "unspecified" or null

The method the user used to authenticate. May be absent on activities recorded before this field was introduced.

  • "social"
  • "unspecified"
  • created_at: optional string

When this activity occurred.

format: date-time

  • mfa_method: optional "not_used" or "unspecified" or null

The second authentication factor performed during this login, if any. null when the second-factor status is not recorded on this event — for example, when authentication was delegated to an external identity provider and any second factor is not visible to Juglow, or when this event is one step of a multistep login whose MFA is reported on another activity. May be absent on activities recorded before this field was introduced.

  • "not_used"
  • "unspecified"
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • StepUpAuthenticationFailed object

An additional identity check failed.

  • type: optional "step_up_authentication_failed"

default: step_up_authentication_failed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • method: "device_key" or "unspecified" or "webauthn"

The verification method the user attempted.

  • "device_key"
  • "unspecified"
  • "webauthn"
  • reason: "challenge_rejected" or "unspecified" or "verification_failed"

Why the attempt failed.

  • "challenge_rejected"
  • "unspecified"
  • "verification_failed"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • trusted_device_id: optional string or null

Identifier of the trusted device the attempt referenced, e.g. "tdev_...". Present only for the device key method.

  • StepUpAuthenticationSucceeded object

The user completed an additional identity check to confirm a sensitive action.

  • type: optional "step_up_authentication_succeeded"

default: step_up_authentication_succeeded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • method: "device_key" or "unspecified" or "webauthn"

The verification method the user completed.

  • "device_key"
  • "unspecified"
  • "webauthn"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • trusted_device_id: optional string or null

Identifier of the trusted device used, e.g. "tdev_...". Present only for the device key method.

  • StepUpCredentialEnrolled object

A user enrolled a passkey for confirming sensitive actions on their account.

  • type: optional "step_up_credential_enrolled"

default: step_up_credential_enrolled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • credential_id: string

Identifier of the enrolled credential, e.g. "sucr_...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SubscriptionCancellationScheduled object

Subscription cancellation was scheduled at end of billing period.

  • type: optional "subscription_cancellation_scheduled"

default: subscription_cancellation_scheduled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SubscriptionQuantityUpdated object

Contracted subscription seat quantity was updated.

  • type: optional "subscription_quantity_updated"

default: subscription_quantity_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • added_seats: number

The number of seats added by this change.

  • new_quantity: number

The contracted seat quantity after this change.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_quantity: optional number or null

The contracted seat quantity before this change.

  • SubscriptionRenewed object

A cancelled subscription was renewed.

  • type: optional "subscription_renewed"

default: subscription_renewed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • billing_interval: optional string or null

Billing interval (e.g. monthly, annual).

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plan_type: optional string or null

Plan type being renewed into (e.g. team).

  • SubscriptionResumed object

A scheduled subscription cancellation was reversed.

  • type: optional "subscription_resumed"

default: subscription_resumed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • SubscriptionStarted object

A new subscription was created (Team or Enterprise).

  • type: optional "subscription_started"

default: subscription_started

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • billing_interval: optional string or null

Billing interval (e.g. monthly, annual).

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • plan_type: optional string or null

Type of subscription started (e.g. team, enterprise).

  • seat_count: optional number or null

Number of seats purchased.

  • SubscriptionUpgraded object

Subscription plan was upgraded (e.g. Team to Enterprise).

  • type: optional "subscription_upgraded"

default: subscription_upgraded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • new_plan: optional string or null

New plan type after upgrade.

  • old_plan: optional string or null

Previous plan type.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • TrustedDeviceCredentialRotated object

The identity-verification credential of a trusted device was rotated to a new key.

  • type: optional "trusted_device_credential_rotated"

default: trusted_device_credential_rotated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • trusted_device_id: string

Identifier of the device whose credential was rotated, e.g. "tdev_...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • TrustedDeviceEnrolled object

A device was enrolled as a trusted device for the user's account. Trusted devices can be used to confirm the user's identity for sensitive actions.

  • type: optional "trusted_device_enrolled"

default: trusted_device_enrolled

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • enrollment_method: "oauth" or "session" or "unspecified"

How the user confirmed their identity when enrolling the device.

  • "oauth"
  • "session"
  • "unspecified"
  • platform: "android" or "haijun_in_slack" or "desktop_app" or 4 more

The kind of client the enrollment request came from.

  • "android"
  • "haijun_in_slack"
  • "desktop_app"
  • "ios"
  • "unspecified"
  • "web_haijun_ai"
  • "web_console"
  • trusted_device_id: string

Identifier of the device that was enrolled, e.g. "tdev_...".

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • TrustedDeviceRevoked object

A trusted device was removed from the user's account.

  • type: optional "trusted_device_revoked"

default: trusted_device_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • reason: "org_member_removed" or "superseded" or "unspecified" or "user_revoked"

Why the device trust was removed.

  • "org_member_removed"
  • "superseded"
  • "unspecified"
  • "user_revoked"
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • revoked_count: optional number or null

Number of devices removed. Set when a security action removed all of the user's trusted devices at once; absent when a single device was removed (see trusted_device_id).

  • trusted_device_id: optional string or null

Identifier of the device that was removed, e.g. "tdev_...". Set when a single device was removed; absent when several devices were removed at once (see revoked_count).

  • TunnelArchived object

An MCP tunnel was archived.

  • type: optional "tunnel_archived"

default: tunnel_archived

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • tunnel_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • TunnelCertificateAdded object

An inner-TLS CA certificate was added to a tunnel.

  • type: optional "tunnel_certificate_added"

default: tunnel_certificate_added

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • certificate_id: string
  • tunnel_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • certificate_fingerprint: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • TunnelCertificateRevoked object

An inner-TLS CA certificate was revoked from a tunnel.

  • type: optional "tunnel_certificate_revoked"

default: tunnel_certificate_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • certificate_id: string
  • tunnel_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • certificate_fingerprint: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • TunnelCreated object

An MCP tunnel was created.

  • type: optional "tunnel_created"

default: tunnel_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • tunnel_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • tunnel_token_id: optional string or null

Id of the tunnel token issued with the tunnel and returned once in the create response; set only when creating the tunnel also issued its token, and absent for a tunnel whose token is revealed separately

  • TunnelTokenMinted object

An OAuth bearer token for the tunnel management API was minted.

  • type: optional "tunnel_token_minted"

default: tunnel_token_minted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • token_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • token_name: optional string or null
  • TunnelTokenRevealed object

The Cloudflare connector secret for a tunnel was revealed to the caller.

  • type: optional "tunnel_token_revealed"

default: tunnel_token_revealed

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • tunnel_id: string
  • tunnel_token_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • TunnelTokenRevoked object

An OAuth bearer token for the tunnel management API was revoked.

  • type: optional "tunnel_token_revoked"

default: tunnel_token_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • token_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • token_name: optional string or null

Name the administrator gave the token when it was created, if any

  • TunnelTokenRotated object

The Cloudflare connector secret for a tunnel was rotated.

tunnel_token_id is the id of the newly-issued token. The previous token is invalidated by the rotation and its id is not recorded here.

  • type: optional "tunnel_token_rotated"

default: tunnel_token_rotated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • tunnel_id: string
  • tunnel_token_id: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • reason: optional string or null
  • UserConsentRecorded object

User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).

  • type: optional "user_consent_recorded"

default: user_consent_recorded

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • consent_type: string
  • entity_id: string
  • entity_type: string
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • UserConsentRevoked object

User revoked a previously granted consent for a specific entity.

  • type: optional "user_consent_revoked"

default: user_consent_revoked

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • consent_id: optional string or null
  • consent_type: optional string or null
  • created_at: optional string

When this activity occurred.

format: date-time

  • entity_id: optional string or null
  • entity_type: optional string or null
  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • HaijunUserRoleUpdated object

A user's role within the organization was changed, or the user was added to or removed from the organization.

  • type: optional "haijun_user_role_updated"

default: haijun_user_role_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • user_email: string

Email of the user whose role was changed

  • user_id: string

ID of the user whose role was changed

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • current_role: optional string or null

If null, then user was removed from the Organization

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • previous_role: optional string or null

If null, then user was added to the Organization

  • HaijunUserSettingsUpdated object

User updated their personal settings.

  • type: optional "haijun_user_settings_updated"

default: haijun_user_settings_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • updates: array of FullName or DisplayName or ArtifactsEnabled or 19 more
  • FullName object

The full name setting was changed.

  • type: optional "full_name"

default: full_name

  • current_value: optional string or null

Setting value immediately after this change

  • previous_value: optional string or null

Setting value immediately before this change

  • DisplayName object

The display name setting was changed.

  • type: optional "display_name"

default: display_name

  • current_value: optional string or null

Setting value immediately after this change

  • previous_value: optional string or null

Setting value immediately before this change

  • ArtifactsEnabled object

The artifacts setting was changed.

  • type: optional "artifacts_enabled"

default: artifacts_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • LatexEnabled object

The LaTeX setting was changed.

  • type: optional "latex_enabled"

default: latex_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • AnalysisToolEnabled object

The analysis tool setting was changed.

  • type: optional "analysis_tool_enabled"

default: analysis_tool_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • ChatSuggestionsEnabled object

The chat suggestions setting was changed.

  • type: optional "chat_suggestions_enabled"

default: chat_suggestions_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • MultimodalPdfsEnabled object

The multimodal PDFs setting was changed.

  • type: optional "multimodal_pdfs_enabled"

default: multimodal_pdfs_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • GdriveEnabled object

The Google Drive setting was changed.

  • type: optional "gdrive_enabled"

default: gdrive_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • WebSearchEnabled object

The web search setting was changed.

  • type: optional "web_search_enabled"

default: web_search_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • GeolocationEnabled object

The geolocation setting was changed.

  • type: optional "geolocation_enabled"

default: geolocation_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • EnabledSaffron object

The memory setting was changed for the user.

  • type: optional "enabled_saffron"

default: enabled_saffron

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • McpToolsEnabled object

The MCP tools setting was changed.

  • type: optional "mcp_tools_enabled"

default: mcp_tools_enabled

  • current_value: optional map[boolean] or null

Setting value immediately after this change

  • previous_value: optional map[boolean] or null

Setting value immediately before this change

  • CliOpPermissionsEnabled object

The CLI operation permissions setting was changed.

  • type: optional "cli_op_permissions_enabled"

default: cli_op_permissions_enabled

  • current_value: optional map[string] or null

Setting value immediately after this change

  • previous_value: optional map[string] or null

Setting value immediately before this change

  • GoogleDriveSearchEnabled object

The Google Drive search setting was changed.

  • type: optional "google_drive_search_enabled"

default: google_drive_search_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • GmailIntegrationEnabled object

The Gmail integration setting was changed.

  • type: optional "gmail_integration_enabled"

default: gmail_integration_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • GoogleCalendarIntegrationEnabled object

The Google Calendar integration setting was changed.

  • type: optional "google_calendar_integration_enabled"

default: google_calendar_integration_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • ThinkingModeEnabled object

The thinking mode setting was changed.

  • type: optional "thinking_mode_enabled"

default: thinking_mode_enabled

  • current_value: optional "adaptive" or "extended" or "off" or "unspecified" or null

Setting value immediately after this change

  • "adaptive"
  • "extended"
  • "off"
  • "unspecified"
  • previous_value: optional "adaptive" or "extended" or "off" or "unspecified" or null

Setting value immediately before this change

  • "adaptive"
  • "extended"
  • "off"
  • "unspecified"
  • ResearchModeEnabled object

The research mode setting was changed.

  • type: optional "research_mode_enabled"

default: research_mode_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • ComputerUseEnabled object

The computer use setting was changed.

  • type: optional "computer_use_enabled"

default: computer_use_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • HaijunAPIInArtifactsEnabled object

The Haijun API in Artifacts setting was changed.

  • type: optional "haijun_api_in_artifacts_enabled"

default: haijun_api_in_artifacts_enabled

  • current_value: optional boolean or null

Setting value immediately after this change

  • previous_value: optional boolean or null

Setting value immediately before this change

  • ConversationPreferences object

The 'conversation_preferences' for the user were updated. Values omitted.

  • type: optional "conversation_preferences"

default: conversation_preferences

  • CoworkGlobalInstructions object

The Cowork global instructions were updated. Values omitted.

  • type: optional "cowork_global_instructions"

default: cowork_global_instructions

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • VerificationEvidenceSubmitted object

Verification evidence was submitted for an organization's verification.

  • type: optional "verification_evidence_submitted"

default: verification_evidence_submitted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • verification_id: string

Tagged ID of the verification the evidence was submitted for.

  • verification_type: string

The type of verification the evidence was submitted for.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • VerificationProgramApplicationCreated object

An organization applied to a verification program.

  • type: optional "verification_program_application_created"

default: verification_program_application_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • program_slug: string

The verification program the organization applied to.

  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • WorkspaceMemberSpendLimitCreated object

A per-member or workspace-default Haijun Code spend limit was created.

  • type: optional "workspace_member_spend_limit_created"

default: workspace_member_spend_limit_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • account_id: optional string or null

Tagged ID of the user (null for workspace-wide default).

  • created_at: optional string

When this activity occurred.

format: date-time

  • limit_action: optional string or null

The action taken when the limit is reached.

  • limit_usd: optional number or null

The spend limit threshold in USD cents.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace.

  • WorkspaceMemberSpendLimitDeleted object

A per-member or workspace-default Haijun Code spend limit was deleted.

  • type: optional "workspace_member_spend_limit_deleted"

default: workspace_member_spend_limit_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • account_id: optional string or null

Tagged ID of the user (null for workspace-wide default).

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

UUID of the deleted spend limit.

  • workspace_id: optional string or null

Tagged ID of the workspace.

  • WorkspaceMemberSpendLimitUpdated object

A per-member Haijun Code spend limit amount was updated.

  • type: optional "workspace_member_spend_limit_updated"

default: workspace_member_spend_limit_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • account_id: optional string or null

Tagged ID of the user (null for workspace-wide default).

  • created_at: optional string

When this activity occurred.

format: date-time

  • new_limit_usd: optional number or null

The new spend limit threshold in USD cents.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

UUID of the spend limit.

  • workspace_id: optional string or null

Tagged ID of the workspace.

  • WorkspaceSpendLimitAlertEmailsUpdated object

Spend limit alert email recipients were updated for a workspace.

  • type: optional "workspace_spend_limit_alert_emails_updated"

default: workspace_spend_limit_alert_emails_updated

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • alert_emails: optional array of string or null

Updated list of alert email addresses.

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace.

  • WorkspaceSpendLimitCreated object

A workspace-level API spend limit was created.

  • type: optional "workspace_spend_limit_created"

default: workspace_spend_limit_created

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • limit_action: optional string or null

The action taken when the limit is reached (notify_only or notify_and_pause).

  • limit_usd: optional number or null

The spend limit threshold in USD cents.

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • workspace_id: optional string or null

Tagged ID of the workspace.

  • WorkspaceSpendLimitDeleted object

A workspace-level API spend limit was deleted.

  • type: optional "workspace_spend_limit_deleted"

default: workspace_spend_limit_deleted

  • actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
  • APIActor object
  • type: optional "api_actor"

default: api_actor

  • api_key_id: string
  • ip_address: string
  • user_agent: string
  • UserActor object
  • type: optional "user_actor"

default: user_actor

  • email_address: string

format: email

  • ip_address: string
  • user_agent: string
  • user_id: string
  • UnauthenticatedUserActor object
  • type: optional "unauthenticated_user_actor"

default: unauthenticated_user_actor

  • ip_address: string
  • user_agent: string
  • unauthenticated_email_address: optional string or null

format: email

  • JuglowActor object
  • type: optional "juglow_actor"

default: juglow_actor

  • email_address: optional string or null

format: email

  • SystemActor object

Automated background processing performed by Juglow systems, acting without a user or customer credential.

  • type: optional "system_actor"

default: system_actor

  • service: optional string or null

Name of the automated process that performed the action, when known.

  • AdminAPIKeyActor object
  • type: optional "admin_api_key_actor"

default: admin_api_key_actor

  • admin_api_key_id: string
  • ip_address: string
  • user_agent: string
  • ServiceAccountActor object
  • type: optional "service_account_actor"

default: service_account_actor

  • ip_address: string
  • service_account_id: string
  • user_agent: string
  • ScimDirectorySyncActor object
  • type: optional "scim_directory_sync_actor"

default: scim_directory_sync_actor

  • directory_id: string
  • workos_event_id: string
  • idp_connection_type: optional string or null
  • FederatedIdentityActor object

A federated external workload authenticated via a verified OIDC token.

Carries the verified issuer, subject, and audience claims from the presented JWT.

  • type: optional "federated_identity_actor"

default: federated_identity_actor

  • issuer: string
  • subject: string
  • audience: optional array of string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • FederatedActor object

An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.

  • type: optional "federated_actor"

default: federated_actor

  • provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
  • FederatedActorAwsProvider object

Asserting party: the AWS account the organization is bound to.

  • type: optional "aws"

default: aws

  • account_id: string
  • signed_principal: string

The AWS-signed ARN of the IAM principal that requested the token.

  • FederatedActorAzureProvider object

Asserting party: the Azure subscription the organization is bound to.

  • type: optional "azure"

default: azure

  • subscription_id: string
  • FederatedActorGcpProvider object

Asserting party: the GCP project the organization is bound to.

  • type: optional "gcp"

default: gcp

  • project_number: string
  • FederatedActorOidcProvider object

Asserting party: a customer-registered OIDC federation issuer.

  • type: optional "oidc"

default: oidc

  • issuer: optional string or null

The federation issuer's URL. Null when the presented credential failed verification.

  • ip_address: optional string or null
  • subject: optional string or null

The provider's verified identifier for the caller; its form depends on the provider.

  • user_agent: optional string or null
  • AttestedDeviceActor object

An attested mobile device authenticated via Apple App Attest.

  • type: optional "attested_device_actor"

default: attested_device_actor

  • external_client_id: string
  • kid_hash: string
  • ip_address: optional string or null
  • user_agent: optional string or null
  • id: optional string

Unique identifier for the activity e.g. 'activity_abcd1234'

  • created_at: optional string

When this activity occurred.

format: date-time

  • organization_id: optional string or null

Organization ID this activity is associated with

  • organization_uuid: optional string or null

Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).

  • spend_limit_id: optional string or null

UUID of the deleted spend limit.

  • workspace_id: optional string or null

Tagged ID of the workspace.

  • first_id: optional string or null
  • has_more: optional boolean

default: false

  • last_id: optional string or null

Example

bash
curl https://haijun.my.id/v1/compliance/activities \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "actor": {
        "api_key_id": "api_key_id",
        "ip_address": "ip_address",
        "user_agent": "user_agent",
        "type": "api_actor"
      },
      "decision": "blocked",
      "id": "id",
      "abuse_session_id": "abuse_session_id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "organization_id": "organization_id",
      "organization_uuid": "organization_uuid",
      "type": "abuse_decision_received"
    }
  ],
  "first_id": "first_id",
  "has_more": true,
  "last_id": "last_id"
}

Compliance API › Organizations

List organizations

GET /v1/compliance/organizations

List organizations under the parent organization.

Returns organizations sorted by creation date in ascending order. Use limit and page to paginate: each response includes has_more and a next_page token to pass on the next request.

Query parameters

  • limit: optional number

Maximum results (default: 1000, max: 1000)

default: 1000, minimum: 1, maximum: 1000

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of organizations sorted by creation date, ascending

  • created_at: string

Organization creation time (RFC 3339 format)

  • name: string

Organization name

  • uuid: string

Unique identifier for the organization (UUID format)

  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: optional string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/organizations \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "created_at": "2025-03-12T18:22:41.123456+00:00",
      "name": "Acme Corp",
      "uuid": "a1b2c3d4-e5f6-4789-a012-3456789abcde"
    }
  ],
  "has_more": true,
  "next_page": "cGFnZV90b2tlbl9leGFtcGxlXzE3MzQ1Njc4OTA="
}

Compliance API › Organizations › Users

List organization users

GET /v1/compliance/organizations/{org_uuid}/users

List current user members of an organization.

Path parameters

  • org_uuid: string

The organization UUID

Query parameters

  • limit: optional number

Maximum results (default: 500, max: 1000)

default: 500, minimum: 1, maximum: 1000

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of current organization members sorted by organization join date ascending

  • id: string

User identifier (tagged ID)

  • created_at: string

User account creation timestamp

format: date-time

  • email: string

User's current email address

  • full_name: string

User's current full name

  • organization_role: "admin" or "billing" or "haijun_code_user" or 8 more

User's built-in role within the organization. This is distinct from any custom RBAC roles that may also be assigned.

  • "admin"
  • "billing"
  • "haijun_code_user"
  • "developer"
  • "managed"
  • "membership_admin"
  • "owner"
  • "parent_org_admin"
  • "parent_org_owner"
  • "primary_owner"
  • "user"
  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/organizations/$ORG_UUID/users \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
      "created_at": "2025-03-12T18:22:41.123456Z",
      "email": "jane.doe@example.com",
      "full_name": "Jane Doe",
      "organization_role": "admin"
    }
  ],
  "has_more": true,
  "next_page": "cGFnZV90b2tlbl9leGFtcGxlXzE3MzQ1Njc4OTA="
}

Compliance API › Organizations › Roles

List Compliance Roles

GET /v1/compliance/organizations/{org_uuid}/roles

List Compliance Roles

Path parameters

  • org_uuid: string

The organization UUID

Query parameters

  • limit: optional number

Maximum results (default: 500, max: 1000)

default: 500, minimum: 1, maximum: 1000

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of roles

  • id: string

Role identifier (tagged ID)

  • created_at: string or null

Role creation timestamp (RFC 3339)

format: date-time

  • description: string

Role description

  • name: string

Role name

  • updated_at: string or null

Role last-updated timestamp (RFC 3339)

format: date-time

  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/organizations/$ORG_UUID/roles \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "rbac_role_01SGBg3kEnZrdsVR2QmyJbvD",
      "created_at": "2025-03-12T18:22:41.123456Z",
      "description": "Full administrative access to organization settings and members",
      "name": "Organization Admin",
      "updated_at": "2025-03-14T09:05:17.456789Z"
    }
  ],
  "has_more": true,
  "next_page": "cGFnZV90b2tlbl9leGFtcGxlXzE3MzQ1Njc4OTA="
}

Get Compliance Role

GET /v1/compliance/organizations/{org_uuid}/roles/{role_id}

Get Compliance Role

Path parameters

  • org_uuid: string

The organization UUID

  • role_id: string

The role ID (tagged ID, e.g., rbac_role_abc123)

Headers

  • "x-api-key": optional string

Returns

  • id: string

Role identifier (tagged ID)

  • created_at: string or null

Role creation timestamp (RFC 3339)

format: date-time

  • description: string

Role description

  • name: string

Role name

  • updated_at: string or null

Role last-updated timestamp (RFC 3339)

format: date-time

Example

bash
curl https://haijun.my.id/v1/compliance/organizations/$ORG_UUID/roles/$ROLE_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "rbac_role_01SGBg3kEnZrdsVR2QmyJbvD",
  "created_at": "2025-03-12T18:22:41.123456Z",
  "description": "Full administrative access to organization settings and members",
  "name": "Organization Admin",
  "updated_at": "2025-03-14T09:05:17.456789Z"
}

Compliance API › Organizations › Roles › Permissions

List Compliance Role Permissions

GET /v1/compliance/organizations/{org_uuid}/roles/{role_id}/permissions

List Compliance Role Permissions

Path parameters

  • org_uuid: string

The organization UUID

  • role_id: string

The role ID (tagged ID, e.g., rbac_role_abc123)

Query parameters

  • limit: optional number

Maximum results (default: 500, max: 1000)

default: 500, minimum: 1, maximum: 1000

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of permissions

  • action: string

Action permitted on the resource

  • resource_id: string

Identifier of the resource the permission applies to

  • resource_type: string

Type of resource the permission applies to

  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/organizations/$ORG_UUID/roles/$ROLE_ID/permissions \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "action": "haijun_code",
      "resource_id": "a1b2c3d4-e5f6-4789-a012-3456789abcde",
      "resource_type": "organization"
    }
  ],
  "has_more": true,
  "next_page": "cGFnZV90b2tlbl9leGFtcGxlXzE3MzQ1Njc4OTA="
}

Compliance API › Organizations › Settings

Get effective organization settings

GET /v1/compliance/organizations/{organization_id}/settings

Retrieve the effective settings for an organization.

Returns the settings currently in force for the given organization — the enforced state after all policies are applied, which may differ from what is configured in the admin console. Settings an organization's administrators cannot change (for example, ones controlled by Juglow policy or not available to the organization) are omitted from the list. Settings that report a compliance arrangement with Juglow are the exception: the HIPAA and Access Transparency settings are always included; the API zero data retention setting is reported for Haijun Console organizations, and the Haijun Code zero data retention and customer-managed encryption keys (CMEK) settings for Haijun Enterprise organizations. Each reports whether the arrangement is in place at the organization level; a retention setting on an individual workspace is not reflected.

The organization must belong to the API key's organization hierarchy; unknown organizations and organizations outside the hierarchy return 404.

Path parameters

  • organization_id: string

The organization's UUID

Headers

  • "x-api-key": optional string

Returns

  • type: optional "effective_organization_settings"

default: effective_organization_settings

  • api_keys: array of object

Compliance API keys configured for the organization hierarchy, ordered by creation time ascending. Key secret values are never included.

  • type: optional "compliance_api_key"

default: compliance_api_key

  • id: string

Unique identifier for the API key.

  • created_at: string

When the key was created.

format: date-time

  • created_by_id: string or null

Identifier of the user who created the key, or null when the key was created by automation or its creator's account no longer exists.

  • is_active: boolean

Whether the key is currently active. A deactivated key is listed for audit visibility but cannot authenticate requests.

  • name: string

The name given to the API key when it was created.

  • scopes: array of string

The permission scopes granted to the key.

  • expires_at: optional string or null

When the key will stop authenticating, or null when the key does not expire.

format: date-time

  • organization_id: string
  • settings: array of Boolean or Integer or String or 3 more
  • Boolean object

A setting whose enforced value is a single true/false flag.

  • type: optional "boolean"

default: boolean

  • name: "access_transparency_enabled" or "ai_powered_artifacts_enabled" or "api_workbench_feedback_collection_enabled" or 59 more
  • "access_transparency_enabled"
  • "ai_powered_artifacts_enabled"
  • "api_workbench_feedback_collection_enabled"
  • "api_zero_data_retention_enabled"
  • "artifact_connectors_enabled"
  • "ask_your_org_enabled"
  • "chat_enabled"
  • "haijun_academy_inference_enabled"
  • "haijun_ai_chat_sharing_enabled"
  • "haijun_ai_feedback_collection_enabled"
  • "haijun_ai_integration_sharing_enabled"
  • "haijun_ai_skill_plugins_scanning_enabled"
  • "haijun_code_desktop_bypass_permissions_enabled"
  • "haijun_code_desktop_enabled"
  • "haijun_code_fast_mode_enabled"
  • "haijun_code_metrics_logging_enabled"
  • "haijun_code_remote_control_enabled"
  • "haijun_code_review_enabled"
  • "haijun_code_routines_enabled"
  • "haijun_code_security_enabled"
  • "haijun_code_trusted_devices_required"
  • "haijun_code_web_enabled"
  • "haijun_code_workflows_enabled"
  • "haijun_design_enabled"
  • "haijun_enterprise_haijun_code_zero_data_retention_enabled"
  • "haijun_in_slack_enabled"
  • "haijun_science_custom_connectors_enabled"
  • "haijun_science_custom_skills_enabled"
  • "haijun_science_enabled"
  • "haijun_science_managed_network_allowlist_enabled"
  • "haijun_science_memory_enabled"
  • "haijun_science_modal_enabled"
  • "haijun_science_scientific_model_endpoints_enabled"
  • "haijun_science_ssh_hosts_enabled"
  • "cmek_enabled"
  • "code_execution_enabled"
  • "code_execution_network_egress_enabled"
  • "connector_tools_default_always_allow"
  • "content_redaction_enabled"
  • "cowork_trusted_devices_required"
  • "desktop_extension_allowlist_enabled"
  • "directory_sync_enabled"
  • "frontier_data_use_enabled"
  • "group_skill_sharing_enabled"
  • "hipaa_compliance_enabled"
  • "inline_visualizations_enabled"
  • "ip_allowlist_enabled"
  • "location_metadata_enabled"
  • "member_usage_dashboard_visible"
  • "memory_enabled"
  • "org_wide_skill_sharing_enabled"
  • "project_sharing_enabled"
  • "public_projects_enabled"
  • "skill_sharing_enabled"
  • "skills_enabled"
  • "sso_haijun_ai_enforced"
  • "sso_console_enforced"
  • "sso_enabled"
  • "third_party_interactive_content_enabled"
  • "user_skill_creation_enabled"
  • "web_search_enabled"
  • "work_across_apps_enabled"
  • value: boolean
  • Integer object

A setting whose enforced value is a whole number; null means no limit is in force.

  • type: optional "integer"

default: integer

  • name: "account_session_duration_seconds"
  • value: number or null
  • String object

A setting whose enforced value is a single string; null means no value is configured.

  • type: optional "string"

default: string

  • name: "haijun_code_default_worker_environment_id" or "haijun_code_default_worker_pool_id"
  • "haijun_code_default_worker_environment_id"
  • "haijun_code_default_worker_pool_id"
  • value: string or null
  • StringList object

A setting whose enforced value is a list of strings.

  • type: optional "string_list"

default: string_list

  • name: "allowed_invite_domains" or "disabled_admin_request_types" or "ip_allowlist_ip_ranges"
  • "allowed_invite_domains"
  • "disabled_admin_request_types"
  • "ip_allowlist_ip_ranges"
  • value: array of string
  • ProvisioningMode object

How organization members are provisioned, resolved to the enforced mode.

A configured mode is reported only while the mechanism that enforces it is active: just-in-time modes require single sign-on to be enabled, and SCIM modes require directory sync to be enabled. Otherwise login_only is reported, regardless of any stored configuration.

  • type: optional "provisioning_mode"

default: provisioning_mode

  • value: "jit_advanced" or "jit_permissive" or "login_only" or 2 more

How organization members are provisioned under SSO.

  • "jit_advanced"
  • "jit_permissive"
  • "login_only"
  • "scim_advanced"
  • "scim_permissive"
  • name: optional "sso_provisioning_mode"

default: sso_provisioning_mode

  • DataRetention object

The data retention periods in force, keyed by the type of data they apply to.

A key of all covers every data type and is exclusive: when present it is the only key. A missing key means no organization-level administrator-configured retention period is in force for that data type; Juglow's service defaults may still apply.

  • type: optional "data_retention"

default: data_retention

  • value: map[Fixed or Indefinite]
  • Fixed object

A fixed retention window measured from each item's last activity.

  • type: optional "fixed"

default: fixed

  • duration: number
  • timescale: "day" or "month"
  • "day"
  • "month"
  • Indefinite object

An indefinite retention period: data is kept with no time limit.

  • type: optional "indefinite"

default: indefinite

  • name: optional "data_retention_periods"

default: data_retention_periods

Example

bash
curl https://haijun.my.id/v1/compliance/organizations/$ORGANIZATION_ID/settings \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "api_keys": [
    {
      "id": "id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "created_by_id": "created_by_id",
      "is_active": true,
      "name": "name",
      "scopes": [
        "string"
      ],
      "expires_at": "2019-12-27T18:11:19.117Z",
      "type": "compliance_api_key"
    }
  ],
  "organization_id": "organization_id",
  "settings": [
    {
      "name": "access_transparency_enabled",
      "value": true,
      "type": "boolean"
    }
  ],
  "type": "effective_organization_settings"
}

Compliance API › Groups

List Compliance Groups

GET /v1/compliance/groups

List Compliance Groups

Query parameters

  • limit: optional number

Maximum results (default: 500, max: 1000)

default: 500, minimum: 1, maximum: 1000

  • name_prefix: optional string

Filter groups by name prefix

default: ""

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of groups

  • id: string

Group identifier (tagged ID)

  • created_at: string or null

Group creation timestamp (RFC 3339)

format: date-time

  • description: string

Group description

  • name: string

Group name

  • roles: array of string or null

Role IDs assigned to this group.

  • source_type: string

How the group was created ('direct' or 'scim')

  • updated_at: string or null

Group last-updated timestamp (RFC 3339)

format: date-time

  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/groups \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
      "created_at": "2025-03-12T18:22:41.123456Z",
      "description": "All members of the engineering organization",
      "name": "Engineering Team",
      "roles": [
        "rbac_role_01SGBg3kEnZrdsVR2QmyJbvD",
        "rbac_role_01HtCd4mFoAseWS3RnzKcwE7"
      ],
      "source_type": "scim",
      "updated_at": "2025-03-14T09:05:17.456789Z"
    }
  ],
  "has_more": true,
  "next_page": "cGFnZV90b2tlbl9leGFtcGxlXzE3MzQ1Njc4OTA="
}

Get Compliance Group

GET /v1/compliance/groups/{group_id}

Get Compliance Group

Path parameters

  • group_id: string

The group ID (tagged ID, e.g., rbac_group_abc123)

Headers

  • "x-api-key": optional string

Returns

  • id: string

Group identifier (tagged ID)

  • created_at: string or null

Group creation timestamp (RFC 3339)

format: date-time

  • description: string

Group description

  • name: string

Group name

  • roles: array of string or null

Role IDs assigned to this group.

  • source_type: string

How the group was created ('direct' or 'scim')

  • updated_at: string or null

Group last-updated timestamp (RFC 3339)

format: date-time

Example

bash
curl https://haijun.my.id/v1/compliance/groups/$GROUP_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "created_at": "2025-03-12T18:22:41.123456Z",
  "description": "All members of the engineering organization",
  "name": "Engineering Team",
  "roles": [
    "rbac_role_01SGBg3kEnZrdsVR2QmyJbvD",
    "rbac_role_01HtCd4mFoAseWS3RnzKcwE7"
  ],
  "source_type": "scim",
  "updated_at": "2025-03-14T09:05:17.456789Z"
}

Compliance API › Groups › Members

List Compliance Group Members

GET /v1/compliance/groups/{group_id}/members

List Compliance Group Members

Path parameters

  • group_id: string

The group ID (tagged ID, e.g., rbac_group_abc123)

Query parameters

  • limit: optional number

Maximum results (default: 500, max: 1000)

default: 500, minimum: 1, maximum: 1000

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of group members

  • created_at: string or null

Membership creation timestamp (RFC 3339)

format: date-time

  • email: string

Member email address

  • updated_at: string or null

Membership last-updated timestamp (RFC 3339)

format: date-time

  • user_id: string

Member user identifier (tagged ID)

  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/groups/$GROUP_ID/members \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "created_at": "2025-03-12T18:22:41.123456Z",
      "email": "jane.doe@example.com",
      "updated_at": "2025-03-14T09:05:17.456789Z",
      "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
    }
  ],
  "has_more": true,
  "next_page": "cGFnZV90b2tlbl9leGFtcGxlXzE3MzQ1Njc4OTA="
}

Compliance API › Apps › Chats

List chats

GET /v1/compliance/apps/chats

Lists chat metadata with filtering capabilities for targeted compliance review. Results are sorted chronologically (time ascending) by the order_by key, with ties broken by id.

Incremental polling with order_by=updated_at returns a chat again after it receives a new message, is moved into or out of a project, or is deleted in haijun.ai. A chat is not guaranteed to be returned again after other edits, such as a rename.

Deprecation notice: Combining user_ids[] with any updated_at. filter is deprecated and will be rejected with HTTP 400 after 2026-09-22. For incremental polling by update time, omit user_ids[] and set order_by=updated_at with after_id cursor pagination — this returns the same chats across the whole organization in a single request stream. For per-user listing, use created_at. filters (or no time filter) with the default order_by. user_ids[] with order_by=updated_at is already rejected.

Query parameters

  • after_id: optional string

Pagination cursor for retrieving the next page of results. To paginate, pass the last_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • before_id: optional string

Pagination cursor for retrieving the previous page of results. To paginate, pass the first_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • created_at: optional object
  • gt: optional string

Filter chats created after this time (RFC 3339 format)

format: date-time

  • gte: optional string

Filter chats created at or after this time (RFC 3339 format)

format: date-time

  • lt: optional string

Filter chats created before this time (RFC 3339 format)

format: date-time

  • lte: optional string

Filter chats created at or before this time (RFC 3339 format)

format: date-time

  • limit: optional number

Maximum results (default: 100, max: 1000)

default: 100, minimum: 1, maximum: 1000

  • order_by: optional "created_at" or "updated_at"

Sort key for results. created_at (default) sorts by chat creation time. updated_at sorts by last update time and is only supported for org-wide queries (omit user_ids[]). For org-wide queries, any time filter must match the sort key: created_at. filters require order_by=created_at, and updated_at. filters require order_by=updated_at.

default: created_at

  • "created_at"
  • "updated_at"
  • organization_ids: optional array of string

Filter by organization IDs (accepts org_... or organization UUID). Enumerate IDs via GET /v1/compliance/organizations.

  • project_ids: optional array of string

Filter by project IDs (accepts haijun_proj_...). Enumerate IDs via GET /v1/compliance/apps/projects. Requires user_ids[]; not supported for org-wide queries.

  • updated_at: optional object
  • gt: optional string

Filter chats updated after this time (RFC 3339 format). Combining updated_at filters with user_ids[] is deprecated and will be rejected after 2026-09-22; for updated_at-windowed polling, omit user_ids[] and use order_by=updated_at with after_id pagination.

format: date-time

  • gte: optional string

Filter chats updated at or after this time (RFC 3339 format). Combining updated_at filters with user_ids[] is deprecated and will be rejected after 2026-09-22; for updated_at-windowed polling, omit user_ids[] and use order_by=updated_at with after_id pagination.

format: date-time

  • lt: optional string

Filter chats updated before this time (RFC 3339 format). Combining updated_at filters with user_ids[] is deprecated and will be rejected after 2026-09-22; for updated_at-windowed polling, omit user_ids[] and use order_by=updated_at with after_id pagination.

format: date-time

  • lte: optional string

Filter chats updated at or before this time (RFC 3339 format). Combining updated_at filters with user_ids[] is deprecated and will be rejected after 2026-09-22; for updated_at-windowed polling, omit user_ids[] and use order_by=updated_at with after_id pagination.

format: date-time

  • user_ids: optional array of string

Filter to chats created by specific users (max 10 per request). Omit for an org-wide query. Enumerate IDs via GET /v1/compliance/organizations/{org_uuid}/users. Deprecated combination: passing user_ids[] together with any updated_at.* filter is deprecated and will be rejected after 2026-09-22. For updated_at-windowed polling, omit user_ids[] and use order_by=updated_at with after_id pagination.

maxItems: 10

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of chat metadata sorted chronologically by the request's order_by key (default created_at), tie break by id

  • id: string

Chat ID

  • created_at: string

Creation timestamp

format: date-time

  • deleted_at: string or null

Deletion timestamp if deleted

format: date-time

  • href: string

URL to view this chat in haijun.ai

  • model: string or null

Model selected for this chat (e.g. 'haijun-opus-5'). May be null for legacy chats that never had a model recorded.

  • name: string

Chat name/title

  • organization_uuid: string

Organization UUID this chat belongs to

  • project_id: string or null

Project ID this chat belongs to

  • updated_at: string

Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in haijun.ai. Other edits, such as renaming the chat, are not guaranteed to change it.

format: date-time

  • user: object or null

The user who created the chat. Null when the API key is restricted to one organization and the creator is no longer a member of it.

  • id: string

User identifier

  • email_address: string

User's email address

  • organization_id: string

Deprecated

Organization ID this chat belongs to

  • first_id: string or null

Opaque pagination cursor for the first chat in the current result set. Pass as before_id on the next request to page backwards. Backward pagination is only supported for per-user queries (user_ids[] set); org-wide queries do not accept before_id. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • has_more: boolean

Whether more records exist beyond the current result set

  • last_id: string or null

Opaque pagination cursor for the last chat in the current result set. Pass as after_id on the next request to page forwards. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "haijun_chat_abc123",
      "name": "Product Requirements Discussion",
      "created_at": "2025-06-07T08:09:10Z",
      "updated_at": "2025-06-07T09:10:11Z",
      "organization_id": "org_abc123",
      "organization_uuid": "abcdef01-2345-6789-abcd-ef0123456789",
      "project_id": "haijun_proj_xyz789",
      "model": "haijun-opus-5",
      "user": {
        "id": "user_xyz456",
        "email_address": "user@example.com"
      },
      "href": "https://haijun.my.id/chat/abcdef01-2345-6789-abcd-ef0123456789"
    }
  ],
  "has_more": false,
  "first_id": "eyJrIjogImNyZWF0ZWRfYXQiLCAidCI6ICIyMDI1LTA2LTA3VDA4OjA5OjEwKzAwOjAwIiwgImlkIjogImFiY2RlZjAxLTIzNDUtNjc4OS1hYmNkLWVmMDEyMzQ1Njc4OSJ9",
  "last_id": "eyJrIjogImNyZWF0ZWRfYXQiLCAidCI6ICIyMDI1LTA2LTA3VDA4OjA5OjEwKzAwOjAwIiwgImlkIjogImFiY2RlZjAxLTIzNDUtNjc4OS1hYmNkLWVmMDEyMzQ1Njc4OSJ9"
}

Delete chat

DELETE /v1/compliance/apps/chats/{haijun_chat_id}

Permanently deletes a chat and all associated messages and files. This is a destructive operation that cannot be undone.

Path parameters

  • haijun_chat_id: string

The chat ID (tagged ID, e.g., haijun_chat_abc123)

Headers

  • "x-api-key": optional string

Returns

  • type: optional "haijun_chat_deleted"

Constant string confirming deletion

default: haijun_chat_deleted

  • id: string

The ID of the Haijun chat that was deleted

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats/$HAIJUN_CHAT_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "haijun_chat_abc123",
  "type": "haijun_chat_deleted"
}

Compliance API › Apps › Chats › Messages

Get chat messages

GET /v1/compliance/apps/chats/{haijun_chat_id}/messages

Retrieves message history and file metadata for a specific chat.

Path parameters

  • haijun_chat_id: string

The chat ID (tagged ID, e.g., haijun_chat_abc123)

Query parameters

  • after_id: optional string

Pagination cursor for retrieving the next page of results. To paginate, pass the last_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • before_id: optional string

Pagination cursor for retrieving the previous page of results. To paginate, pass the first_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • created_at: optional object
  • gt: optional string

Filter messages created after this time (RFC 3339 format)

format: date-time

  • gte: optional string

Filter messages created at or after this time (RFC 3339 format)

format: date-time

  • lt: optional string

Filter messages created before this time (RFC 3339 format)

format: date-time

  • lte: optional string

Filter messages created at or before this time (RFC 3339 format)

format: date-time

  • limit: optional number

Maximum results (max: 1000). When omitted, the full result set is returned in one response.

minimum: 1, maximum: 1000

  • order: optional "asc" or "desc"

Sort direction for messages within the response. asc (the default) returns oldest-first; desc returns newest-first.

default: asc

  • "asc"
  • "desc"
  • tool_result_max_chars: optional number

Maximum characters returned per tool-result text item. Items longer than this are shortened and the block's truncated field is set. Pass -1 to disable the limit.

default: 10000, minimum: -1

  • tool_use_input_max_chars: optional number

Maximum characters of JSON-encoded tool input returned per tool_use block. Inputs longer than this are shortened and the block's truncated field is set. Pass -1 to disable the limit.

default: 10000, minimum: -1

  • updated_at: optional object
  • gt: optional string

Filter messages updated after this time (RFC 3339 format)

format: date-time

  • gte: optional string

Filter messages updated at or after this time (RFC 3339 format)

format: date-time

  • lt: optional string

Filter messages updated before this time (RFC 3339 format)

format: date-time

  • lte: optional string

Filter messages updated at or before this time (RFC 3339 format)

format: date-time

Headers

  • "x-api-key": optional string

Returns

  • id: string

Chat ID

  • chat_messages: array of object

Array of chat messages in order of created_at

  • id: string

Unique identifier for the message e.g. 'haijun_chat_msg_abcd1234'

  • artifacts: array of object or null

Versioned documents generated or updated by the assistant in this message. Download via GET /v1/compliance/apps/artifacts/{artifact_version_id}/content.

  • id: string

Artifact ID e.g. 'haijun_artifact_abc123'

  • artifact_type: string or null

MIME-like artifact type e.g. 'application/vnd.ant.code'

  • title: string or null

Artifact title

  • version_id: string

Artifact version ID e.g. 'haijun_artifact_version_abc123'

  • content: array of Text or ToolUse or ToolResult

Content blocks within the message

  • Text object

Text content block.

  • type: "text"

default: text

  • text: string

Text content from human or assistant

  • thinking_redacted: boolean

True when content enclosed in the assistant's internal-reasoning tags (or the tag markup itself) was removed from text during export. Removal never occurs with this field false. Always false on human messages, whose text is exported verbatim.

default: false

  • truncated: boolean

True when text was shortened by the server's fixed per-string bound (1 MiB). Always false on chat text blocks.

default: false

  • ToolUse object

Tool invocation requested by the assistant.

  • type: "tool_use"

default: tool_use

  • id: string or null

Tool-use ID, e.g. 'toolu_01AbC...'

  • input: string

Arguments passed to the tool, as a JSON-encoded string. May be shortened — see the truncated field

  • integration_name: string or null

Name of the integration that provides this tool, when applicable

  • mcp_server_url: string or null

Base URL (scheme, host, and path only) of the MCP server that provides this tool, when applicable

  • name: string

Name of the tool invoked

  • truncated: boolean

True when input was shortened. Pass the endpoint's tool-use input max parameter as -1 to request full content, subject to any server-side maximum the endpoint enforces.

default: false

  • ToolResult object

Result returned by a tool invocation.

  • type: "tool_result"

default: tool_result

  • content: array of object

Text content returned by the tool. Generated files are surfaced via the message's generated_files list; other non-text item types (including images and links) are omitted.

  • type: "text"

default: text

  • text: string

Text returned by the tool

  • integration_name: string or null

Name of the integration that provides this tool, when applicable

  • is_error: boolean

True when the tool reported an error

  • mcp_server_url: string or null

Base URL (scheme, host, and path only) of the MCP server that provides this tool, when applicable

  • name: string

Name of the tool that produced this result

  • tool_use_id: string or null

ID of the tool_use block this result responds to

  • truncated: boolean

True when one or more text items in content were shortened. Pass the endpoint's tool-result max parameter as -1 to request full content, subject to any server-side maximum the endpoint enforces.

default: false

  • created_at: string

Message creation timestamp - For human: when they sent the message, For assistant: when it completed the last content block

format: date-time

  • files: array of object or null

Binary file attachments uploaded by the user. Download via GET /v1/compliance/apps/chats/files/{haijun_file_id}/content.

  • id: string

File ID

  • created_at: string

File creation timestamp

format: date-time

  • filename: string

Display name of the file

  • md5: string or null

Lowercase hex MD5 of the file's preferred downloadable variant, as recorded at upload time. Null when no stored hash is available.

  • mime_type: string or null

MIME type of the file's preferred downloadable variant (e.g. 'application/pdf')

  • size_bytes: number or null

Size in bytes of the file's preferred downloadable variant, if known. Null for older files uploaded before size was recorded.

  • generated_files: array of object or null

Downloadable files the assistant created via tool use (e.g. PDF, spreadsheet, slide deck). Distinct from files, which are uploads attached to the message. Download an entry whose id starts with haijun_gen_file_ via GET /v1/compliance/apps/chats/generated-files/{haijun_gen_file_id}/content, and one whose id starts with haijun_file_ via GET /v1/compliance/apps/chats/files/{haijun_file_id}/content.

  • id: string

Id of the file: either a generated-file id, e.g. 'haijun_gen_file_abc123', or a file id, e.g. 'haijun_file_abc123'; the prefix tells them apart. Download the first from the generated-files content endpoint and the second from the files content endpoint. Treat everything after the prefix as an opaque string; the encoding may change without notice.

  • filename: string

Display name of the generated file

  • md5: string or null

Lowercase hex MD5 of the generated file, when available. Null when no stored hash is available.

  • mime_type: string or null

MIME type of the file, when known

  • size_bytes: number or null

Size in bytes of the generated file, when available. Null when the file has expired or size is not recorded.

  • role: "assistant" or "user"

Message sender (user or assistant)

  • "assistant"
  • "user"
  • created_at: string

Creation timestamp

format: date-time

  • deleted_at: string or null

Deletion timestamp if deleted

format: date-time

  • first_id: string or null

Opaque pagination cursor for the first message in the current result set. Pass as before_id on the next request to page backwards. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • has_more: boolean

Whether more chat messages exist beyond the current result set. Use last_id as after_id in a follow-up request to page forward.

default: false

  • href: string

URL to view this chat in haijun.ai

  • last_id: string or null

Opaque pagination cursor for the last message in the current result set. Pass as after_id on the next request to page forwards. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • model: string or null

Model selected for this chat (e.g. 'haijun-opus-5'). May be null for legacy chats that never had a model recorded.

  • name: string

Chat name

  • organization_uuid: string

Organization UUID this chat belongs to

  • project_id: string or null

Project ID this chat belongs to

  • updated_at: string

Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in haijun.ai. Other edits, such as renaming the chat, are not guaranteed to change it.

format: date-time

  • user: object or null

The user who created the chat. Null when the API key is restricted to one organization and the creator is no longer a member of it.

  • id: string

User identifier

  • email_address: string

User's email address

  • organization_id: string

Deprecated

Organization ID this chat belongs to

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats/$HAIJUN_CHAT_ID/messages \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "haijun_chat_abc123",
  "name": "Product Requirements Discussion",
  "created_at": "2025-06-07T08:09:10Z",
  "updated_at": "2025-06-07T08:09:11Z",
  "organization_id": "org_abc123",
  "organization_uuid": "abcdef01-2345-6789-abcd-ef0123456789",
  "project_id": "haijun_proj_xyz789",
  "model": "haijun-opus-5",
  "user": {
    "id": "user_xyz456",
    "email_address": "user@example.com"
  },
  "href": "https://haijun.my.id/chat/abcdef01-2345-6789-abcd-ef0123456789",
  "chat_messages": [
    {
      "id": "haijun_chat_msg_abc123",
      "role": "user",
      "created_at": "2025-06-07T08:09:10Z",
      "content": [
        {
          "type": "text",
          "text": "Can you help me draft requirements for our new dashboard feature?"
        }
      ],
      "files": [
        {
          "id": "haijun_file_xyz789",
          "filename": "dashboard_mockup_v1.pdf",
          "mime_type": "application/pdf",
          "size_bytes": 12345,
          "md5": "5d41402abc4b2a76b9719d911017c592",
          "created_at": "2025-06-07T08:09:10Z"
        }
      ]
    },
    {
      "id": "haijun_chat_msg_def456",
      "role": "assistant",
      "created_at": "2025-06-07T08:09:11Z",
      "content": [
        {
          "type": "text",
          "text": "I'd be happy to help you draft requirements for your dashboard feature..."
        }
      ],
      "artifacts": [
        {
          "id": "haijun_artifact_abc123",
          "version_id": "haijun_artifact_version_xyz789",
          "title": "Dashboard Requirements Draft",
          "artifact_type": "text/markdown"
        }
      ]
    }
  ],
  "has_more": false,
  "first_id": "eyJtc2dfdXVpZCI6ICIwZjcwYjA2Ni0uLi4ifQ==",
  "last_id": "eyJtc2dfdXVpZCI6ICJhNGUwYjE3Mi0uLi4ifQ=="
}

Compliance API › Apps › Chats › Files

Get file metadata

GET /v1/compliance/apps/chats/files/{haijun_file_id}

Retrieves metadata for a file referenced in chat messages, without downloading the file content. Use the sibling /content endpoint to download the bytes.

Path parameters

  • haijun_file_id: string

The file ID (tagged ID, e.g., haijun_file_abc123)

Headers

  • "x-api-key": optional string

Returns

  • id: string

File ID

  • haijun_chat_ids: array of string

Chats this file is attached to. A file can be referenced by messages across multiple chats.

  • created_at: string

File creation timestamp

format: date-time

  • filename: string or null

Display name of the file, if set

  • md5: string or null

Lowercase hex MD5 of the file's preferred downloadable variant, as recorded at upload time. Null when no stored hash is available. The sibling /content endpoint also sets a Content-MD5 header (base64 per RFC 1864) computed over the exact served bytes; when the two disagree, the header is authoritative.

  • message_ids: array of string

Chat message IDs this file is attached to. A file can be referenced by multiple messages.

  • mime_type: string or null

MIME type of the file's preferred downloadable variant (e.g. 'application/pdf'). May be null for files with no downloadable content (e.g. code-interpreter outputs).

  • size_bytes: number or null

Size in bytes of the file's preferred downloadable variant, if known

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats/files/$HAIJUN_FILE_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "haijun_file_xyz789",
  "filename": "quarterly_report.pdf",
  "mime_type": "application/pdf",
  "size_bytes": 1048576,
  "md5": "5d41402abc4b2a76b9719d911017c592",
  "created_at": "2024-01-15T10:30:00Z",
  "message_ids": [
    "haijun_chat_msg_abc123"
  ],
  "haijun_chat_ids": [
    "haijun_chat_def456"
  ]
}

Delete file

DELETE /v1/compliance/apps/chats/files/{haijun_file_id}

Permanently deletes a specific file. This is a destructive operation that cannot be undone.

Path parameters

  • haijun_file_id: string

The file ID (tagged ID, e.g., haijun_file_abc123)

Headers

  • "x-api-key": optional string

Returns

  • type: optional "haijun_file_deleted"

Constant string confirming deletion

default: haijun_file_deleted

  • id: string

The ID of the file that was deleted

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats/files/$HAIJUN_FILE_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "haijun_file_xyz789",
  "type": "haijun_file_deleted"
}

Download file content

GET /v1/compliance/apps/chats/files/{haijun_file_id}/content

Downloads the binary content of a file referenced in chat messages.

Path parameters

  • haijun_file_id: string

The file ID (tagged ID, e.g., haijun_file_abc123)

Headers

  • "x-api-key": optional string

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats/files/$HAIJUN_FILE_ID/content \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"

Compliance API › Apps › Chats › Generated Files

Get Haijun-generated file metadata

GET /v1/compliance/apps/chats/generated-files/{haijun_gen_file_id}

Returns metadata for a file the assistant created via tool use.

Use the sibling /content endpoint to download the bytes.

Path parameters

  • haijun_gen_file_id: string

The generated-file id (e.g., 'haijun_gen_file_abc123') as returned in chat_messages[].generated_files[].id from GET /apps/chats/{haijun_chat_id}/messages.

Headers

  • "x-api-key": optional string

Returns

  • id: string

Opaque generated-file id, e.g. 'haijun_gen_file_abc123'.

  • haijun_chat_id: string

The chat this generated file belongs to

  • created_at: string or null

File creation timestamp, when available

format: date-time

  • filename: string

Display name of the generated file

  • md5: string or null

Lowercase hex MD5 of the stored file. Null when no stored hash is available. The sibling /content endpoint also sets a Content-MD5 header (base64 per RFC 1864) computed over the exact served bytes.

  • mime_type: string or null

MIME type of the stored file, when available

  • size_bytes: number or null

Size in bytes of the stored file, when available

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats/generated-files/$HAIJUN_GEN_FILE_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "id",
  "haijun_chat_id": "haijun_chat_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "filename": "filename",
  "md5": "md5",
  "mime_type": "mime_type",
  "size_bytes": 0
}

Download a Haijun-generated file

GET /v1/compliance/apps/chats/generated-files/{haijun_gen_file_id}/content

Downloads the binary content of a file the assistant created via tool use.

Path parameters

  • haijun_gen_file_id: string

The generated-file id (e.g., 'haijun_gen_file_abc123') as returned in chat_messages[].generated_files[].id from GET /apps/chats/{haijun_chat_id}/messages.

Headers

  • "x-api-key": optional string

Example

bash
curl https://haijun.my.id/v1/compliance/apps/chats/generated-files/$HAIJUN_GEN_FILE_ID/content \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"

Compliance API › Apps › Projects

List projects

GET /v1/compliance/apps/projects

Lists project metadata with filtering capabilities. Results are sorted chronologically (time ascending) by created_at.

Query parameters

  • created_at: optional object
  • gt: optional string

Filter projects created after this time (RFC 3339 format)

format: date-time

  • gte: optional string

Filter projects created at or after this time (RFC 3339 format)

format: date-time

  • lt: optional string

Filter projects created before this time (RFC 3339 format)

format: date-time

  • lte: optional string

Filter projects created at or before this time (RFC 3339 format)

format: date-time

  • limit: optional number

Maximum results (default: 20, max: 100)

default: 20, minimum: 1, maximum: 100

  • organization_ids: optional array of string

Filter by organization IDs (accepts org_... or organization UUID). Enumerate IDs via GET /v1/compliance/organizations.

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • updated_at: optional object
  • gt: optional string

Filter projects updated after this time (RFC 3339 format)

format: date-time

  • gte: optional string

Filter projects updated at or after this time (RFC 3339 format)

format: date-time

  • lt: optional string

Filter projects updated before this time (RFC 3339 format)

format: date-time

  • lte: optional string

Filter projects updated at or before this time (RFC 3339 format)

format: date-time

  • user_ids: optional array of string

Filter by user IDs. Enumerate IDs via GET /v1/compliance/organizations/{org_uuid}/users.

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

List of projects sorted by creation date ascending

  • id: string

Project identifier (tagged ID)

  • created_at: string

Project creation timestamp

format: date-time

  • deleted_at: string or null

Timestamp when the project was deleted by an end user, or null otherwise

format: date-time

  • is_private: boolean

If false, the project is visible to all organization members; if true the project is accessible only to the creator and specified collaborators

  • name: string

Project name

  • organization_uuid: string

Organization UUID this project belongs to

  • updated_at: string

Project last update timestamp

format: date-time

  • user: object or null

Project creator information, or null if the creator's account has been deleted or the creator is no longer a member of an organization the key may read

  • id: string

User identifier (tagged ID)

  • email_address: string

User's email address

  • organization_id: string

Deprecated

Organization identifier (tagged ID)

  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "haijun_proj_abc123",
      "name": "Q4 Product Planning",
      "created_at": "2025-06-01T10:00:00Z",
      "updated_at": "2025-06-15T14:30:00Z",
      "is_private": true,
      "organization_id": "org_abc123",
      "organization_uuid": "abc12345-6789-0abc-def0-123456789abc",
      "user": {
        "id": "user_xyz456",
        "email_address": "user@example.com"
      }
    }
  ],
  "has_more": true,
  "next_page": "page_eyJjcmVhdGVkX2F0IjoiMjAyNS0wNi0wMVQxMDowMDowMFoiLCJ1dWlkIjoiYWJjMTIzIn0="
}

Get project details

GET /v1/compliance/apps/projects/{project_id}

Get detailed information for a specific project.

Path parameters

  • project_id: string

The project ID (tagged ID, e.g., haijun_proj_abc123)

Headers

  • "x-api-key": optional string

Returns

  • id: string

Project identifier (tagged ID)

  • attachments_count: number

Number of attachments contained within this project

  • chats_count: number

Number of chats contained within this project

  • created_at: string

Project creation timestamp

format: date-time

  • deleted_at: string or null

Timestamp when the project was deleted by an end user, or null otherwise

format: date-time

  • description: string

Project description

  • instructions: string

Project's custom instructions / prompt

  • is_private: boolean

If false, the project is visible to all organization members; if true the project is accessible only to the creator and specified collaborators

  • name: string

Project name

  • organization_uuid: string

Organization UUID this project belongs to

  • updated_at: string

Project last update timestamp

format: date-time

  • user: object or null

Project creator information, or null if the creator's account has been deleted or the creator is no longer a member of an organization the key may read

  • id: string

User identifier (tagged ID)

  • email_address: string

User's email address

  • organization_id: string

Deprecated

Organization identifier (tagged ID)

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects/$PROJECT_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "haijun_proj_01Nm7PqRsTuVwXyZaBcDeFgH",
  "attachments_count": 3,
  "chats_count": 14,
  "created_at": "2025-03-12T18:22:41.123456Z",
  "deleted_at": "2019-12-27T18:11:19.117Z",
  "description": "Planning and research for the Q3 launch",
  "instructions": "Focus on concise, actionable answers.",
  "is_private": true,
  "name": "Q3 Product Launch",
  "organization_id": "org_015eofRkKpogX7uDKUyvBTph",
  "organization_uuid": "a1b2c3d4-e5f6-4789-a012-3456789abcde",
  "updated_at": "2025-03-14T09:05:17.456789Z",
  "user": {
    "id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
    "email_address": "jane.doe@example.com"
  }
}

Delete project

DELETE /v1/compliance/apps/projects/{project_id}

Delete a project for compliance purposes.

Hard-deletes the project and all its associated data including:

  • All project documents and files
  • All role assignments
  • Knowledge base (if RAG is enabled)
  • Sync sources

Project must have no attached chats - returns 409 if chats exist.

Path parameters

  • project_id: string

The project ID (tagged ID, e.g., haijun_proj_abc123)

Headers

  • "x-api-key": optional string

Returns

  • type: optional "haijun_project_deleted"

Constant string confirming deletion.

default: haijun_project_deleted

  • id: string

The ID of the Haijun project that was deleted

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects/$PROJECT_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "id",
  "type": "haijun_project_deleted"
}

Compliance API › Apps › Projects › Attachments

List project attachments

GET /v1/compliance/apps/projects/{project_id}/attachments

List files and documents attached to a project.

List files and project documents attached to the project referenced by project_id. This includes the IDs of attached files, and attached project documents.

The raw binary content of attached files can be downloaded using the GET /v1/compliance/apps/chats/files/{haijun_file_id}/content endpoint.

The text content of attached project documents can be fetched using the GET /v1/compliance/apps/projects/documents/{haijun_proj_doc_id} endpoint.

Path parameters

  • project_id: string

The project ID (tagged ID, e.g., haijun_proj_abc123)

Query parameters

  • limit: optional number

Maximum results (default: 20, max: 100)

default: 20, minimum: 1, maximum: 100

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of ComplianceProjectFileReference or ComplianceProjectDocReference

List of attachments sorted chronologically by created_at, tie break by id

  • ComplianceProjectFileReference object

File attachment reference for compliance responses.

  • type: "project_file"

Discriminator marking this as a binary file

default: project_file

  • id: string

File identifier (e.g., 'haijun_file_abcd')

  • created_at: string

Creation timestamp (RFC 3339 format)

format: date-time

  • filename: string

Display name of the file (e.g., 'document.pdf')

  • md5: string or null

Lowercase hex MD5 of the file's preferred downloadable variant, when recorded. Null otherwise. Use the per-file /metadata endpoint for the authoritative value.

  • mime_type: string

MIME type of the file's preferred downloadable variant when one is recorded, else 'application/octet-stream'. Use the per-file /metadata endpoint for the authoritative value.

  • size_bytes: number or null

Size in bytes of the file's preferred downloadable variant, when recorded. Null otherwise. Use the per-file /metadata endpoint for the authoritative value.

  • ComplianceProjectDocReference object

Project document attachment reference for compliance responses.

  • type: "project_doc"

Discriminator marking this as a plain text document

default: project_doc

  • id: string

Project document identifier (e.g., 'haijun_proj_doc_abcd')

  • created_at: string

Creation timestamp (RFC 3339 format)

format: date-time

  • filename: string

Display name of the document (e.g., 'document.txt')

  • mime_type: "text/plain"

MIME type of the project document, always set to plain text

default: text/plain

  • updated_at: string or null

Last-modified timestamp of the document. Reserved for future use — currently always null.

format: date-time

  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

To get the next page, use the 'next_page' from the current response as the 'page' in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects/$PROJECT_ID/attachments \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "filename": "filename",
      "md5": "md5",
      "mime_type": "mime_type",
      "size_bytes": 0,
      "type": "project_file"
    }
  ],
  "has_more": true,
  "next_page": "next_page"
}

Compliance API › Apps › Projects › Collaborators

List project collaborators

GET /v1/compliance/apps/projects/{project_id}/collaborators

List the users, groups, and organization-wide grants on a project.

Each entry represents one active role assignment on the project. Principals are returned as a discriminated union on type — an individual user, an RBAC group, the whole organization, or all holders of an organization-level role.

Path parameters

  • project_id: string

The project ID (tagged ID, e.g., haijun_proj_abc123)

Query parameters

  • limit: optional number

Maximum results (default: 20, max: 100)

default: 20, minimum: 1, maximum: 100

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

Headers

  • "x-api-key": optional string

Returns

  • data: array of ComplianceProjectUserCollaborator or ComplianceProjectGroupCollaborator or ComplianceProjectOrganizationCollaborator or ComplianceProjectOrganizationRoleCollaborator

List of collaborators sorted chronologically by granted_at, tie break by the underlying role-assignment UUID

  • ComplianceProjectUserCollaborator object

An individual user granted a role on a project.

  • type: "user"

Discriminator marking this as an individual user collaborator

default: user

  • granted_at: string

When this collaborator was granted access (RFC 3339 format)

format: date-time

  • role: "admin" or "editor" or "owner" or "viewer"

Role granted on the project

  • "admin"
  • "editor"
  • "owner"
  • "viewer"
  • user_id: string or null

Identifier of the user granted access (tagged ID), or null if their account has since been deleted

  • ComplianceProjectGroupCollaborator object

An RBAC group granted a role on a project.

  • type: "group"

Discriminator marking this as a group collaborator

default: group

  • granted_at: string

When this collaborator was granted access (RFC 3339 format)

format: date-time

  • group_id: string

Identifier of the group granted access (tagged ID)

  • role: "admin" or "editor" or "owner" or "viewer"

Role granted on the project

  • "admin"
  • "editor"
  • "owner"
  • "viewer"
  • ComplianceProjectOrganizationCollaborator object

An entire organization granted a role on a project.

  • type: "organization"

Discriminator marking this as an organization-wide grant

default: organization

  • granted_at: string

When this collaborator was granted access (RFC 3339 format)

format: date-time

  • organization_uuid: string

UUID of the organization granted access

  • role: "admin" or "editor" or "owner" or "viewer"

Role granted on the project

  • "admin"
  • "editor"
  • "owner"
  • "viewer"
  • ComplianceProjectOrganizationRoleCollaborator object

All holders of an organization-level role granted a role on a project.

  • type: "organization_role"

Discriminator marking this as a grant to all organization members holding a specific org-level role

default: organization_role

  • granted_at: string

When this collaborator was granted access (RFC 3339 format)

format: date-time

  • organization_role: string

The organization-level role whose holders are granted access

  • role: "admin" or "editor" or "owner" or "viewer"

Role granted on the project

  • "admin"
  • "editor"
  • "owner"
  • "viewer"
  • has_more: boolean

Whether more records exist beyond the current result set

  • next_page: string or null

To get the next page, use the 'next_page' from the current response as the 'page' in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects/$PROJECT_ID/collaborators \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "granted_at": "2019-12-27T18:11:19.117Z",
      "role": "admin",
      "type": "user",
      "user_id": "user_id"
    }
  ],
  "has_more": true,
  "next_page": "next_page"
}

Compliance API › Apps › Projects › Documents

Get project document content

GET /v1/compliance/apps/projects/documents/{document_id}

Get detailed information for a specific project document.

Path parameters

  • document_id: string

The document ID (tagged ID, e.g., haijun_proj_doc_abc123)

Headers

  • "x-api-key": optional string

Returns

  • id: string

Project document identifier (tagged ID)

  • content: string

Document text content

  • created_at: string

Document creation timestamp

format: date-time

  • filename: string

Document filename

  • user: object or null

Document creator information, or null if the creator's account has been deleted or the creator is no longer a member of an organization the key may read

  • id: string

User identifier (tagged ID)

  • email_address: string

User's email address

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects/documents/$DOCUMENT_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "haijun_proj_doc_01Qr8StUvWxYzAbCdEfGhJjK",
  "content": "# Design notes\n\n- Item one\n- Item two\n",
  "created_at": "2025-03-12T18:22:41.123456Z",
  "filename": "design-notes.txt",
  "user": {
    "id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
    "email_address": "jane.doe@example.com"
  }
}

Get project document metadata

GET /v1/compliance/apps/projects/documents/{document_id}/metadata

Returns metadata for a project document, without the content body.

Use the sibling GET /v1/compliance/apps/projects/documents/{document_id} endpoint to fetch the document text. The md5 and size_bytes fields here are computed over the UTF-8 encoding of that text, so a DLP consumer can dedupe or match hashes without downloading every document.

Path parameters

  • document_id: string

The document ID (tagged ID, e.g., haijun_proj_doc_abc123)

Headers

  • "x-api-key": optional string

Returns

  • id: string

Project document identifier (tagged ID)

  • haijun_project_id: string

The project this document belongs to

  • created_at: string

Document creation timestamp

format: date-time

  • filename: string

Document filename

  • md5: string

Lowercase hex MD5 of the document content (UTF-8 encoded). Matches the content field returned by the sibling content endpoint.

  • mime_type: "text/plain"

MIME type of the document content, always plain text

default: text/plain

  • size_bytes: number

Size in bytes of the document content (UTF-8 encoded)

  • user: object or null

Document creator information, or null if the creator's account has been deleted or the creator is no longer a member of an organization the key may read

  • id: string

User identifier (tagged ID)

  • email_address: string

User's email address

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects/documents/$DOCUMENT_ID/metadata \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "id",
  "haijun_project_id": "haijun_project_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "filename": "filename",
  "md5": "md5",
  "mime_type": "text/plain",
  "size_bytes": 0,
  "user": {
    "id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
    "email_address": "jane.doe@example.com"
  }
}

Delete project document

DELETE /v1/compliance/apps/projects/documents/{document_id}

Delete a project document for compliance purposes.

Hard-deletes the project document permanently.

Path parameters

  • document_id: string

The document ID (tagged ID, e.g., haijun_proj_doc_abc123)

Headers

  • "x-api-key": optional string

Returns

  • type: "haijun_project_document_deleted"

Constant string confirming deletion.

default: haijun_project_document_deleted

  • id: string

The ID of the project document that was deleted

Example

bash
curl https://haijun.my.id/v1/compliance/apps/projects/documents/$DOCUMENT_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "id",
  "type": "haijun_project_document_deleted"
}

Compliance API › Apps › Artifacts

Get artifact metadata

GET /v1/compliance/apps/artifacts/{artifact_version_id}

Returns metadata for an artifact version, without the content body.

Use the sibling /content endpoint to fetch the artifact text. The md5 and size_bytes fields here are computed over the UTF-8 encoding of that text, so a DLP consumer can dedupe or match hashes without downloading every artifact.

Path parameters

  • artifact_version_id: string

The artifact version ID (tagged ID, e.g., haijun_artifact_version_abc123)

Headers

  • "x-api-key": optional string

Returns

  • id: string

Artifact ID e.g. 'haijun_artifact_abc123'

  • artifact_type: string or null

MIME-like artifact type e.g. 'application/vnd.ant.code'

  • haijun_chat_id: string

The chat this artifact belongs to

  • created_at: string

Artifact version creation timestamp

format: date-time

  • md5: string

Lowercase hex MD5 of the artifact content (UTF-8 encoded). Matches the content field returned by the sibling /content endpoint.

  • size_bytes: number

Size in bytes of the artifact content (UTF-8 encoded)

  • title: string or null

Artifact title

  • version_id: string

Artifact version ID e.g. 'haijun_artifact_version_abc123'

Example

bash
curl https://haijun.my.id/v1/compliance/apps/artifacts/$ARTIFACT_VERSION_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "id",
  "artifact_type": "artifact_type",
  "haijun_chat_id": "haijun_chat_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "md5": "md5",
  "size_bytes": 0,
  "title": "title",
  "version_id": "version_id"
}

Download artifact content

GET /v1/compliance/apps/artifacts/{artifact_version_id}/content

Download the content of an artifact version for compliance purposes.

Returns the full text content of the artifact version.

Path parameters

  • artifact_version_id: string

The artifact version ID (tagged ID, e.g., haijun_artifact_version_abc123)

Headers

  • "x-api-key": optional string

Example

bash
curl https://haijun.my.id/v1/compliance/apps/artifacts/$ARTIFACT_VERSION_ID/content \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"

Compliance API › Apps › Sessions › Local

List local sessions

GET /v1/compliance/apps/sessions/local

List local sessions across the organizations the key may read.

Results are ordered by created_at descending. Pagination is forward-only via next_page; there is no reverse cursor.

Query parameters

  • created_at: optional object
  • gte: optional string

Only return sessions whose first inference call is at or after this time (RFC 3339; a UTC offset is required).

format: date-time

  • lt: optional string

Only return sessions whose first inference call is strictly before this time (RFC 3339; a UTC offset is required).

format: date-time

  • limit: optional number

Maximum results (default: 100, max: 500)

default: 100, minimum: 1, maximum: 500

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • updated_at: optional object
  • gte: optional string

Only return sessions whose last inference call is at or after this time (RFC 3339; a UTC offset is required). Combines with created_at.gte / created_at.lt; the ordering and pagination are unchanged. Use it to poll for sessions that have been active since a previous pass — a session that becomes active later can only enter the result, never leave it.

format: date-time

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

Page of local sessions, ordered by created_at descending; ties are broken by a fixed server-side order. updated_at never participates in the ordering; the updated_at.gte query parameter filters on it without changing the order or the pagination cursor.

  • type: "compliance_local_session"

default: compliance_local_session

  • id: string

Local session identifier, prefixed clls_. Unique within the parent organization. Treat as an opaque string; the format may change without notice.

  • created_at: string

Timestamp of the session's first retained inference call (RFC 3339, UTC). When a session's activity spans the child organization's retention boundary, calls older than the boundary are no longer reflected, so this value is the timestamp of the earliest retained call: always strictly after the boundary, never the boundary itself.

format: date-time

  • organization_uuid: string

UUID of the child organization the session belongs to

  • product_surface: string or null

The product the session ran in: cowork (Cowork in Haijun Desktop on the user's machine), haijun_code (Haijun Code), haijun_science (Haijun Science), haijun_in_chrome (the Haijun in Chrome browser extension's built-in chat), or one of office_agents/excel, office_agents/powerpoint, office_agents/word, and office_agents/outlook (Haijun for Microsoft 365, by app; office_agents alone when the app is not identified). New values appear as coverage expands; treat unrecognized values as opaque. null when the surface was not recorded.

  • truncated: boolean

True when the session has more inference calls than the service can return for one session (100,000). The messages endpoint then returns only the session's earliest calls, up to that many, and ends before the session does; updated_at is a lower bound on the latest call and can differ between the list and retrieve endpoints. False for every session within that bound.

default: false

  • updated_at: string

Timestamp of the session's last retained inference call (RFC 3339, UTC). Always at or after created_at. When a session's activity spans the child organization's retention boundary, calls older than the boundary are no longer reflected — but because retention removes only the oldest calls, this value (unlike created_at) is unaffected until the entire session has aged out. On the list endpoint this value is a lower bound: for a session still active at a page or created_at.lt window boundary it can momentarily lag the session's true last activity. Retrieving the session, or its messages, always reflects the exact latest retained call.

format: date-time

  • user: object

The authenticated user at the time of the session. Always set; user.id is always populated. user.email_address is null when the user's account has been deleted or the user is no longer a member of an organization the key may read.

  • id: string

User identifier (tagged ID, prefixed user_). Always set, so attribution survives after the user's account is deleted or the user leaves the organizations the key may read.

  • email_address: string or null

User's email address. Null when the user's account has been deleted or the user is no longer a member of an organization the key may read. The messages endpoint does not resolve email addresses; this field is always null there.

  • workspace_id: string or null

Workspace identifier (tagged ID, prefixed wrkspc_). Null for sessions not attributed to a workspace.

  • next_page: string or null

Opaque pagination cursor (prefixed page_) for the next page. Null when there is no further page. Treat as an opaque string; the format may change without notice.

Example

bash
curl https://haijun.my.id/v1/compliance/apps/sessions/local \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "type": "compliance_local_session",
      "id": "clls_eyJ2IjoxLCJvIjoiOWEx…",
      "organization_uuid": "9a1e0000-0000-0000-0000-000000000000",
      "workspace_id": "wrkspc_01SvYKoWVRVHoEbwESNvzYdR",
      "user": {
        "id": "user_01GpKpLmNoPqRsTuVwXyZaBc",
        "email_address": "engineer@example.com"
      },
      "product_surface": "cowork",
      "created_at": "2026-07-09T14:02:11Z",
      "updated_at": "2026-07-09T15:47:33Z"
    }
  ]
}

Retrieve a local session

GET /v1/compliance/apps/sessions/local/{local_session_id}

Retrieve one local session.

The response is the same session object the list endpoint returns, with user.email_address resolved the same way. Retention is enforced when the response is served: a session whose every inference call has aged out returns 404.

Path parameters

  • local_session_id: string

Headers

  • "x-api-key": optional string

Returns

  • type: "compliance_local_session"

default: compliance_local_session

  • id: string

Local session identifier, prefixed clls_. Unique within the parent organization. Treat as an opaque string; the format may change without notice.

  • created_at: string

Timestamp of the session's first retained inference call (RFC 3339, UTC). When a session's activity spans the child organization's retention boundary, calls older than the boundary are no longer reflected, so this value is the timestamp of the earliest retained call: always strictly after the boundary, never the boundary itself.

format: date-time

  • organization_uuid: string

UUID of the child organization the session belongs to

  • product_surface: string or null

The product the session ran in: cowork (Cowork in Haijun Desktop on the user's machine), haijun_code (Haijun Code), haijun_science (Haijun Science), haijun_in_chrome (the Haijun in Chrome browser extension's built-in chat), or one of office_agents/excel, office_agents/powerpoint, office_agents/word, and office_agents/outlook (Haijun for Microsoft 365, by app; office_agents alone when the app is not identified). New values appear as coverage expands; treat unrecognized values as opaque. null when the surface was not recorded.

  • truncated: boolean

True when the session has more inference calls than the service can return for one session (100,000). The messages endpoint then returns only the session's earliest calls, up to that many, and ends before the session does; updated_at is a lower bound on the latest call and can differ between the list and retrieve endpoints. False for every session within that bound.

default: false

  • updated_at: string

Timestamp of the session's last retained inference call (RFC 3339, UTC). Always at or after created_at. When a session's activity spans the child organization's retention boundary, calls older than the boundary are no longer reflected — but because retention removes only the oldest calls, this value (unlike created_at) is unaffected until the entire session has aged out. On the list endpoint this value is a lower bound: for a session still active at a page or created_at.lt window boundary it can momentarily lag the session's true last activity. Retrieving the session, or its messages, always reflects the exact latest retained call.

format: date-time

  • user: object

The authenticated user at the time of the session. Always set; user.id is always populated. user.email_address is null when the user's account has been deleted or the user is no longer a member of an organization the key may read.

  • id: string

User identifier (tagged ID, prefixed user_). Always set, so attribution survives after the user's account is deleted or the user leaves the organizations the key may read.

  • email_address: string or null

User's email address. Null when the user's account has been deleted or the user is no longer a member of an organization the key may read. The messages endpoint does not resolve email addresses; this field is always null there.

  • workspace_id: string or null

Workspace identifier (tagged ID, prefixed wrkspc_). Null for sessions not attributed to a workspace.

Example

bash
curl https://haijun.my.id/v1/compliance/apps/sessions/local/$LOCAL_SESSION_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "type": "compliance_local_session",
  "id": "clls_eyJ2IjoxLCJvIjoiOWEx…",
  "organization_uuid": "9a1e0000-0000-0000-0000-000000000000",
  "workspace_id": "wrkspc_01SvYKoWVRVHoEbwESNvzYdR",
  "user": {
    "id": "user_01GpKpLmNoPqRsTuVwXyZaBc",
    "email_address": "engineer@example.com"
  },
  "product_surface": "cowork",
  "created_at": "2026-07-09T14:02:11Z",
  "updated_at": "2026-07-09T15:47:33Z"
}

Compliance API › Apps › Sessions › Local › Messages

Retrieve local session messages

GET /v1/compliance/apps/sessions/local/{local_session_id}/messages

Read one local session's transcript, oldest-first by default.

Retention is enforced read-side: turns at or before the child organization's retention boundary are never returned; a session that straddles the boundary carries one leading content_unavailable placeholder (reason: "retention_elapsed") in their place. The boundary is pinned on the walk's first page and honored for 24 hours: a cursor older than that is rejected with an explicit 400; restart the walk to read under the current boundary.

On a very large session, some pages are too large to read and return a 400; retrying does not help. If the request used order=desc, read the session oldest first from its first page instead (omit order and page, then follow next_page). Rarely, an oldest-first page returns this 400 too; contact Juglow support and quote the request-id response header.

Path parameters

  • local_session_id: string

Query parameters

  • limit: optional number

Maximum results (default: 100, max: 1000)

default: 100, minimum: 1, maximum: 1000

  • order: optional "asc" or "desc"

Sort direction. asc (oldest-first, default) or desc. On very large sessions some pages are too large to read and return a 400, far more often with desc; read those sessions with asc, starting again from the first page.

default: asc

  • "asc"
  • "desc"
  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • tool_result_max_bytes: optional number

Truncate each text item inside a tool result to at most this many bytes (cut on a code-point boundary). Pass -1 to request the server maximum (approximately 1 MiB); larger values are clamped to it. 0 is not a valid value.

default: 10000, minimum: -1, maximum: 2147483647

  • tool_use_input_max_bytes: optional number

Truncate each tool-use input to at most this many bytes (cut on a code-point boundary so the result is valid UTF-8). Pass -1 to request the server maximum (approximately 1 MiB); larger values are clamped to it. 0 is not a valid value.

default: 10000, minimum: -1, maximum: 2147483647

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

Transcript turns for this page, in call order: oldest call first by default, newest call first with order=desc. The messages of one call carry the call's timestamp and follow each other in transcript order; a page boundary can fall between them.

  • type: "compliance_local_session_message"

default: compliance_local_session_message

  • id: string

Message identifier, prefixed clsm_. Stable for as long as the message's turn is retained: identifiers of retained turns do not change as older turns age out of the organization's retention period. The retention_elapsed placeholder's identifier is distinct from every retained turn's and changes only when further turns age out.

  • content: array of Text or ToolUse or ToolResult

Content blocks within the message, discriminated on type (text / tool_use / tool_result: the same discriminator values as the haijun.ai chat-messages endpoint; the tool variants omit integration_name and mcp_server_url, and text carries truncated). Extended-thinking content is never included. The request's system field is never included; a presence-only marker message is emitted when it was set. The request's tools[] definitions are never included as transcript messages. Project-level instructions (such as HAIJUN.md files) appear in the message stream as a user-role context block and are included. Empty when provenance.type is content_unavailable.

  • Text object

Text content block.

  • type: "text"

default: text

  • text: string

Text content from the user or the assistant

  • truncated: boolean

True when text was shortened by the server's fixed per-string bound (approximately 1 MiB), or when ancillary content the block carried (such as citations) was omitted, or when this block stands in for a non-text block whose content is not shown, or when it is an explanatory marker the server inserted (its text enclosed in square brackets, e.g. prefacing client-asserted history). There is no request parameter that raises the per-string bound.

default: false

  • ToolUse object

Tool invocation requested by the assistant.

  • type: "tool_use"

default: tool_use

  • id: string or null

Tool-use ID, e.g. 'toolu_01AbC...'

  • input: string

Arguments passed to the tool, as a JSON-encoded string. May be shortened (see the truncated field); a truncated value is cut mid-document and is not valid JSON.

  • name: string

Name of the tool invoked

  • truncated: boolean

True when input was shortened. Pass tool_use_input_max_bytes=-1 to request the server maximum.

default: false

  • ToolResult object

Result returned by a tool invocation.

  • type: "tool_result"

default: tool_result

  • content: array of object

Text content returned by the tool. Non-text item types are omitted and signalled via truncated with an in-band item-count marker.

  • type: "text"

default: text

  • text: string

Text returned by the tool

  • is_error: boolean

True when the tool reported an error

  • name: string

Name of the tool that produced this result

  • tool_use_id: string or null

ID of the tool_use block this result responds to

  • truncated: boolean

True when one or more text items in content were shortened or non-text items were omitted. Pass tool_result_max_bytes=-1 to request the server maximum.

default: false

  • created_at: string

When the message was recorded (RFC 3339, UTC)

format: date-time

  • model: string or null

The model that served this assistant turn, as reported in the model field of the underlying Messages API response. Null on user messages and on any assistant message whose provenance is set: client-asserted history and synthetic markers were not produced by a model during this session, and for unavailable content the serving model is not known.

  • provenance: ContentUnavailable or ClientAsserted or SyntheticMarker or null

Where this turn's content came from, discriminated on type. Null (the common case) means verified content: on an assistant message, content Haijun produced during this session; on a user message, content the user sent. content_unavailable: the turn's content cannot be returned and content is empty; reason says why. client_asserted: assistant content the client supplied as conversation history; content shows what the model received but its authorship is not verified; never on user-role messages. synthetic_marker: a transcript marker the endpoint generated rather than content either party sent during the session. Both client_asserted and synthetic_marker can result from normal request or client processing, not only client modification. Callers should tolerate unrecognized type values.

  • ContentUnavailable object

The turn's content cannot be returned; content is empty.

  • type: "content_unavailable"

default: content_unavailable

  • reason: string

Why this turn's content cannot be returned, e.g. not_captured (the content was not captured for compliance retrieval), client_aborted (the client closed the connection or cancelled the request before the response completed, so the response was not captured for this turn; any partial output already streamed to the client is not included; assistant-role turns only), cmek_key_revoked (the content is encrypted under the organization's customer-managed key and that key is unavailable), retention_elapsed (the content lies past the organization's retention boundary; on the placeholder standing in for every pre-boundary turn), or oversize (the message exceeds the server's per-message size bound even after per-block truncation). Callers should tolerate unrecognized values. not_captured is not proof that no record was stored: content withheld by the storage layer's fail-closed access policies carries the same reason and is deliberately indistinguishable from content that was never captured.

  • ClientAsserted object

Assistant content the client supplied as conversation history rather than produced by Haijun during this session. content shows what the model received but its authorship is not verified; this can result from normal request or client processing, not only client modification. Never on user-role messages.

  • type: "client_asserted"

default: client_asserted

  • SyntheticMarker object

A transcript marker generated by the endpoint rather than sent by either party during the session. Marker messages indicate that the prompt history diverged from what was captured, that the request's system field was present but is not shown, or that earlier turns that a request re-sent as history were withheld because they cannot be dated against the child organization's data-retention period (only for organizations with a finite retention period; the request's new user input after its last assistant turn is not affected). The marker's text names the cause. Markers that report a mismatch with captured history can result from normal request or client processing, not only client modification.

  • type: "synthetic_marker"

default: synthetic_marker

  • role: "assistant" or "user"

Message sender (user or assistant)

  • "assistant"
  • "user"
  • next_page: string or null

Opaque pagination cursor (prefixed page_) for the next page. Null when there is no further page. Treat as an opaque string; the format may change without notice.

  • session: object

The local session the messages belong to. user.email_address is always null on this endpoint; the messages endpoint does not resolve email addresses.

  • type: "compliance_local_session"

default: compliance_local_session

  • id: string

Local session identifier, prefixed clls_. Unique within the parent organization. Treat as an opaque string; the format may change without notice.

  • created_at: string

Timestamp of the session's first retained inference call (RFC 3339, UTC). When a session's activity spans the child organization's retention boundary, calls older than the boundary are no longer reflected, so this value is the timestamp of the earliest retained call: always strictly after the boundary, never the boundary itself.

format: date-time

  • organization_uuid: string

UUID of the child organization the session belongs to

  • product_surface: string or null

The product the session ran in: cowork (Cowork in Haijun Desktop on the user's machine), haijun_code (Haijun Code), haijun_science (Haijun Science), haijun_in_chrome (the Haijun in Chrome browser extension's built-in chat), or one of office_agents/excel, office_agents/powerpoint, office_agents/word, and office_agents/outlook (Haijun for Microsoft 365, by app; office_agents alone when the app is not identified). New values appear as coverage expands; treat unrecognized values as opaque. null when the surface was not recorded.

  • truncated: boolean

True when the session has more inference calls than the service can return for one session (100,000). The messages endpoint then returns only the session's earliest calls, up to that many, and ends before the session does; updated_at is a lower bound on the latest call and can differ between the list and retrieve endpoints. False for every session within that bound.

default: false

  • updated_at: string

Timestamp of the session's last retained inference call (RFC 3339, UTC). Always at or after created_at. When a session's activity spans the child organization's retention boundary, calls older than the boundary are no longer reflected — but because retention removes only the oldest calls, this value (unlike created_at) is unaffected until the entire session has aged out. On the list endpoint this value is a lower bound: for a session still active at a page or created_at.lt window boundary it can momentarily lag the session's true last activity. Retrieving the session, or its messages, always reflects the exact latest retained call.

format: date-time

  • user: object

The authenticated user at the time of the session. Always set; user.id is always populated. user.email_address is null when the user's account has been deleted or the user is no longer a member of an organization the key may read.

  • id: string

User identifier (tagged ID, prefixed user_). Always set, so attribution survives after the user's account is deleted or the user leaves the organizations the key may read.

  • email_address: string or null

User's email address. Null when the user's account has been deleted or the user is no longer a member of an organization the key may read. The messages endpoint does not resolve email addresses; this field is always null there.

  • workspace_id: string or null

Workspace identifier (tagged ID, prefixed wrkspc_). Null for sessions not attributed to a workspace.

Example

bash
curl https://haijun.my.id/v1/compliance/apps/sessions/local/$LOCAL_SESSION_ID/messages \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "clsm_eyJ2IjoxLCJsIjoi…",
      "content": [
        {
          "text": "text",
          "truncated": true,
          "type": "text"
        }
      ],
      "created_at": "2025-03-12T18:22:41.123456Z",
      "model": "haijun-opus-5",
      "provenance": {
        "reason": "not_captured",
        "type": "content_unavailable"
      },
      "role": "assistant",
      "type": "compliance_local_session_message"
    }
  ],
  "next_page": "page_eyJ2IjoxLCJmIjoibSIs…",
  "session": {
    "id": "clls_eyJ2IjoxLCJvIjoiOWEx…",
    "created_at": "2025-03-12T18:22:41.123456Z",
    "organization_uuid": "a1b2c3d4-e5f6-4789-a012-3456789abcde",
    "product_surface": "cowork",
    "truncated": true,
    "type": "compliance_local_session",
    "updated_at": "2025-03-12T18:22:41.123456Z",
    "user": {
      "id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
      "email_address": "jane.doe@example.com"
    },
    "workspace_id": "wrkspc_01SvYKoWVRVHoEbwESNvzYdR"
  }
}

Compliance API › Apps › Sessions › Remote

List remote sessions

GET /v1/compliance/apps/sessions/remote

List remote sessions (Cowork sessions that run in Juglow-managed cloud environments) across the organizations the key may read.

Each entry carries session metadata only; retrieve a session's transcript from the messages endpoint. By default the list spans every such organization; pass up to 500 organization_ids[] values to narrow it. Pass 1 to 10 user_ids[] values to scope the list to specific users: that filter matches the session's owning user, so agent-owned sessions are excluded whenever it is set. Bound results in time with the created_at range parameters (created_at.gte, created_at.gt, created_at.lt, created_at.lte; RFC 3339). There is no updated_at filter.

Results are sorted newest first by created_at, with at most limit sessions per page (default 100, maximum 500). Pagination is forward-only: pass the response's next_page value back as page to retrieve the next page, and stop when next_page is null.

Query parameters

  • created_at: optional object
  • gt: optional string

Filter remote sessions created after this time (RFC 3339 format)

format: date-time

  • gte: optional string

Filter remote sessions created at or after this time (RFC 3339 format)

format: date-time

  • lt: optional string

Filter remote sessions created before this time (RFC 3339 format)

format: date-time

  • lte: optional string

Filter remote sessions created at or before this time (RFC 3339 format)

format: date-time

  • limit: optional number

Maximum results (default: 100, max: 500)

default: 100, minimum: 1, maximum: 500

  • organization_ids: optional array of string

Filter to specific child organization identifiers. Omit to enumerate every child organization the key may read.

maxItems: 500

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • user_ids: optional array of string

Filter to sessions owned by specific users (max 10 per request). Agent-owned sessions are excluded when this filter is set.

maxItems: 10

Headers

  • "x-api-key": optional string

Returns

  • data: array of object
  • id: string

Remote session identifier

  • agent_id: string or null

Identifier of the automated agent that owns the session. Null for user-owned sessions. At most one of user and agent_id is set.

  • haijun_project_id: string or null

ID of the project the session is bound to. Null when the session has no project binding.

  • created_at: string

When the session was created (RFC 3339, UTC)

format: date-time

  • organization_uuid: string

UUID of the organization the session belongs to

  • product_surface: string or null

The Haijun product the session was created from. Currently cowork_remote, for Cowork sessions started on haijun.ai web or mobile. More values will appear as other surfaces launch, so treat any unrecognized value as an unclassified surface rather than an error. Null for sessions created before this field was recorded, for surfaces that do not stamp it, and for unrecognized tag values.

  • started_by_user: object or null

The user who initiated an agent-owned session (for example, by mentioning Haijun in Slack or via a scheduled trigger). Null for user-owned sessions — where the session's user started it — and for agent sessions with no human initiator. For initiators no longer a member of an organization the key may read, the object is populated with email_address null.

  • id: string

User identifier

  • email_address: string or null

User's email address. Null when the user is no longer a member of an organization the key may read — id remains set so attribution is preserved. The messages endpoint does not resolve email addresses; this field is always null there.

  • status: string

Session lifecycle state. One of active, paused, archived, or failed — the lifecycle states the owning product surface exposes — plus pending, a brief transient state that resolves before any transcript content exists. The list endpoint includes pending; the messages endpoint returns 404 for it. Deleted sessions are not returned on either endpoint. Treat unrecognized values as an unknown state rather than an error.

  • updated_at: string

When the session was last modified (RFC 3339, UTC)

format: date-time

  • user: object or null

The user who owns the session. Null for sessions owned by an automated agent rather than a user. At most one of user and agent_id is set. For users no longer a member of an organization the key may read, the object is populated with email_address null.

  • id: string

User identifier

  • email_address: string or null

User's email address. Null when the user is no longer a member of an organization the key may read — id remains set so attribution is preserved. The messages endpoint does not resolve email addresses; this field is always null there.

  • next_page: string or null

Opaque page token; pass as page to retrieve the next page. Null when no rows exist after this page. Treat this value as opaque; do not parse or store it long-term, as the format may change without notice.

Example

bash
curl https://haijun.my.id/v1/compliance/apps/sessions/remote \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "cse_01A0000000000000000000000",
      "organization_uuid": "00000000-0000-0000-0000-000000000000",
      "user": {
        "id": "user_01A0000000000000000000000",
        "email_address": "user@example.com"
      },
      "status": "active",
      "created_at": "2026-01-02T03:04:05.000000Z",
      "updated_at": "2026-01-02T03:04:05.000000Z",
      "product_surface": "cowork_remote",
      "haijun_project_id": "haijun_proj_01Nm7PqRsTuVwXyZaBcDeFgH"
    }
  ],
  "next_page": "page_AAE..."
}

Compliance API › Apps › Sessions › Remote › Messages

Retrieve remote session messages

GET /v1/compliance/apps/sessions/remote/{haijun_remote_session_id}/messages

Retrieve one remote session's transcript: user prompts, assistant responses, and tool calls and results. Thinking blocks and images are not included.

Messages are returned oldest first by default; pass order=desc to reverse. Pagination uses the same page/next_page scheme as the list endpoint, with at most limit messages per page (default 100, maximum 1000); keep paginating until next_page is null. tool_use_input_max_bytes and tool_result_max_bytes cap how many bytes of each tool-use input and each tool-result text item are returned; a block shortened by either cap carries truncated: true.

The response embeds the session's metadata under session alongside the paginated data array. On this endpoint session.user.email_address and session.started_by_user are always null; read them from the list endpoint instead.

Returns 404 while the session is still pending, for deleted sessions, and for sessions outside the organizations the key may read. A malformed session identifier returns 400.

Path parameters

  • haijun_remote_session_id: string

The remote session identifier (cse_...) to retrieve

Query parameters

  • limit: optional number

Maximum results (default: 100, max: 1000)

default: 100, minimum: 1, maximum: 1000

  • order: optional "asc" or "desc"

Sort direction. asc (oldest-first) or desc.

default: asc

  • "asc"
  • "desc"
  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • tool_result_max_bytes: optional number

Truncate each text item inside a tool result to at most this many bytes (cut on a code-point boundary). Pass -1 to request the server maximum. 0 is not a valid value.

default: 10000, minimum: -1, maximum: 2147483647

  • tool_use_input_max_bytes: optional number

Truncate each tool-use input to at most this many bytes (cut on a code-point boundary so the result is valid UTF-8). Pass -1 to request the server maximum. 0 is not a valid value.

default: 10000, minimum: -1, maximum: 2147483647

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

Transcript turns for this page, ordered by transcript position. created_at is a commit timestamp and may tie or invert under concurrent writes; do not re-sort by it.

  • id: string

Unique identifier for the message, e.g. csev_abc123

  • content: array of Text or ToolUse or ToolResult

Content blocks within the message

  • Text object

Text content block.

  • type: "text"

default: text

  • text: string

Text content from the user or the assistant

  • truncated: boolean

True when text exceeded the server-defined maximum (approximately 1 MiB) and was shortened.

default: false

  • ToolUse object

Tool invocation requested by the assistant.

  • type: "tool_use"

default: tool_use

  • id: string or null

Tool-use ID, e.g. 'toolu_01AbC...'

  • input: string

Arguments passed to the tool, as a JSON-encoded string. May be shortened — see the truncated field

  • name: string

Name of the tool invoked

  • truncated: boolean

True when input was shortened. Pass tool_use_input_max_bytes=-1 to request full content, subject to the server-side maximum.

default: false

  • ToolResult object

Result returned by a tool invocation.

  • type: "tool_result"

default: tool_result

  • content: array of object

Text content returned by the tool. Non-text item types are omitted.

  • type: "text"

default: text

  • text: string

Text returned by the tool

  • is_error: boolean

True when the tool reported an error

  • name: string

Name of the tool that produced this result

  • tool_use_id: string or null

ID of the tool_use block this result responds to

  • truncated: boolean

True when one or more text items in content were shortened. Pass tool_result_max_bytes=-1 to request full content, subject to the server-side maximum.

default: false

  • content_unavailable: boolean

True when the stored content could not be returned — it could not be decrypted, or it exceeded the server's per-event size bound. content is empty in that case; this distinguishes 'no content' from 'content withheld'.

default: false

  • created_at: string

When the message was recorded (RFC 3339, UTC)

format: date-time

  • role: "assistant" or "user"

Message sender (user or assistant)

  • "assistant"
  • "user"
  • sent_by_user_id: string or null

Identifier of the human account that sent this turn on an agent-owned session. Null on user-owned sessions, where every user-role turn was sent by the session's user.

  • next_page: string or null

Opaque page token; pass as page to retrieve the next page. Null when no rows exist after this page. Treat this value as opaque; do not parse or store it long-term, as the format may change without notice.

  • session: object

Session metadata. started_by_user, user.email_address, and haijun_project_id are always null on this endpoint; the messages endpoint resolves neither email addresses nor project bindings.

  • id: string

Remote session identifier

  • agent_id: string or null

Identifier of the automated agent that owns the session. Null for user-owned sessions. At most one of user and agent_id is set.

  • haijun_project_id: string or null

ID of the project the session is bound to. Null when the session has no project binding.

  • created_at: string

When the session was created (RFC 3339, UTC)

format: date-time

  • organization_uuid: string

UUID of the organization the session belongs to

  • product_surface: string or null

The Haijun product the session was created from. Currently cowork_remote, for Cowork sessions started on haijun.ai web or mobile. More values will appear as other surfaces launch, so treat any unrecognized value as an unclassified surface rather than an error. Null for sessions created before this field was recorded, for surfaces that do not stamp it, and for unrecognized tag values.

  • started_by_user: object or null

The user who initiated an agent-owned session (for example, by mentioning Haijun in Slack or via a scheduled trigger). Null for user-owned sessions — where the session's user started it — and for agent sessions with no human initiator. For initiators no longer a member of an organization the key may read, the object is populated with email_address null.

  • id: string

User identifier

  • email_address: string or null

User's email address. Null when the user is no longer a member of an organization the key may read — id remains set so attribution is preserved. The messages endpoint does not resolve email addresses; this field is always null there.

  • status: string

Session lifecycle state. One of active, paused, archived, or failed — the lifecycle states the owning product surface exposes — plus pending, a brief transient state that resolves before any transcript content exists. The list endpoint includes pending; the messages endpoint returns 404 for it. Deleted sessions are not returned on either endpoint. Treat unrecognized values as an unknown state rather than an error.

  • updated_at: string

When the session was last modified (RFC 3339, UTC)

format: date-time

  • user: object or null

The user who owns the session. Null for sessions owned by an automated agent rather than a user. At most one of user and agent_id is set. For users no longer a member of an organization the key may read, the object is populated with email_address null.

  • id: string

User identifier

  • email_address: string or null

User's email address. Null when the user is no longer a member of an organization the key may read — id remains set so attribution is preserved. The messages endpoint does not resolve email addresses; this field is always null there.

Example

bash
curl https://haijun.my.id/v1/compliance/apps/sessions/remote/$HAIJUN_REMOTE_SESSION_ID/messages \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "id",
      "content": [
        {
          "text": "text",
          "truncated": true,
          "type": "text"
        }
      ],
      "content_unavailable": true,
      "created_at": "2019-12-27T18:11:19.117Z",
      "role": "assistant",
      "sent_by_user_id": "sent_by_user_id"
    }
  ],
  "next_page": "next_page",
  "session": {
    "id": "id",
    "agent_id": "agent_id",
    "haijun_project_id": "haijun_project_id",
    "created_at": "2019-12-27T18:11:19.117Z",
    "organization_uuid": "organization_uuid",
    "product_surface": "product_surface",
    "started_by_user": {
      "id": "id",
      "email_address": "email_address"
    },
    "status": "status",
    "updated_at": "2019-12-27T18:11:19.117Z",
    "user": {
      "id": "id",
      "email_address": "email_address"
    }
  }
}

Compliance API › Code › Artifacts

List Code Artifacts

GET /v1/compliance/apps/code/artifacts

List Haijun Code Artifacts owned by organizations under the parent organization.

Results are sorted by Artifact identifier. Pages may be short or empty while next_page is still set — continue until next_page is absent. Artifacts are sorted by identifier (not creation time): an Artifact published during an export may land before the cursor and be omitted, so for a point-in-time-complete export re-enumerate after publishing quiesces.

Artifacts owned by a since-deleted child organization are not returned.

Query parameters

  • limit: optional number

Maximum results (default: 20, max: 100)

default: 20, minimum: 1, maximum: 100

  • organization_ids: optional array of string

Filter by organization IDs (accepts org_... or organization UUID, up to 500). Enumerate IDs via GET /v1/compliance/organizations.

maxItems: 500

  • page: optional string

Opaque pagination token from a previous response's next_page field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.

  • updated_at: optional object
  • gt: optional string

Return only Artifacts updated after this time (RFC 3339 format). See updated_at.gte for the completeness caveat.

format: date-time

  • gte: optional string

Return only Artifacts updated at or after this time (RFC 3339 format). Time filters match an eventually-consistent index and Artifacts published before this field was recorded never match — omit the time filter for compliance-complete enumeration. For incremental export, apply a generous overlap margin between windows and dedupe by id: adjacent tiling silently misses items whose index update lagged their publish.

format: date-time

  • lt: optional string

Return only Artifacts updated before this time (RFC 3339 format). Multiple time operators are AND-ed to the tightest bound. See updated_at.gte for the completeness caveat.

format: date-time

  • lte: optional string

Return only Artifacts updated at or before this time (RFC 3339 format). See updated_at.gte for the completeness caveat.

format: date-time

  • user_ids: optional array of string

Filter by owner user IDs (up to 200). Enumerate IDs via GET /v1/compliance/organizations/{org_uuid}/users.

maxItems: 200

Headers

  • "x-api-key": optional string

Returns

  • data: array of object

Page of Artifacts

  • id: string

Artifact identifier (tagged ID)

  • organization_uuid: string

Organization UUID this Artifact belongs to

  • owner_user_id: string or null

Artifact owner's user identifier (tagged ID), or null for Artifacts published by an agent session rather than a user account. When set, it survives after the owner's account is deleted or the owner leaves every organization under the parent.

  • published_version_id: string or null

Identifier of the version a non-owner viewer would render when read_mode permits them — the version the owner has pinned for non-owner readers if one is pinned, otherwise the owner's latest. When read_mode is owner no non-owner renders any version; the field still reports which version would be served were read_mode widened.

  • read_mode: "org" or "owner" or "public" or "users"

Who can view this Artifact: only its owner, a named set of users, every member of its organization, or anyone on the internet (public)

  • "org"
  • "owner"
  • "public"
  • "users"
  • updated_at: string or null

Artifact last update timestamp, or null for Artifacts published before this field was recorded

format: date-time

  • user: object or null

Artifact owner with email, or null if the Artifact was published by an agent session, the owner's account has been deleted, or the owner is no longer a member of an organization the key may read

  • id: string

User identifier (tagged ID)

  • email_address: string

User's email address

  • versions: array of object

Up to roughly 20 most-recently-published versions of this Artifact (older versions are not retained). Metadata only — use GET /v1/compliance/apps/code/artifacts/{artifact_id}/versions/{version_id} to download a version's content.

  • id: string

Opaque version identifier

  • created_at: string or null

When this version was published

format: date-time

  • name: string

Artifact title at this version. Falls back to the version identifier when the title for an older version is no longer retained.

  • has_more: boolean

Whether next_page is set. May be true for a page whose next page is empty — continue until next_page is absent.

  • next_page: string or null

Token to retrieve the next page. Use this as the 'page' parameter in your next request

Example

bash
curl https://haijun.my.id/v1/compliance/apps/code/artifacts \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "data": [
    {
      "id": "cart_01Tu9VwXyZaBcDeFgHiJkLmN",
      "organization_uuid": "a1b2c3d4-e5f6-4789-a012-3456789abcde",
      "owner_user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
      "published_version_id": "1741803761-9f3a",
      "read_mode": "org",
      "updated_at": "2025-03-14T09:05:17.456789Z",
      "user": {
        "id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
        "email_address": "jane.doe@example.com"
      },
      "versions": [
        {
          "id": "1741803761-9f3a",
          "created_at": "2025-03-12T18:22:41.123456Z",
          "name": "Team dashboard"
        }
      ]
    }
  ],
  "has_more": true,
  "next_page": "cGFnZV90b2tlbl9leGFtcGxlXzE3MzQ1Njc4OTA="
}

Download Code Artifact Version Content

GET /v1/compliance/apps/code/artifacts/{artifact_id}/versions/{version_id}

Streams the content of one version of a Haijun Code Artifact as the response body.

Returns 404 for Artifacts that don't exist or belong to another parent organization. A listed version id can start returning 404 if subsequent publishes rotated it out of retained history — re-list on 404. Returns 503 while the version's content upload is still in flight or was abandoned — retry with backoff. Oversized encoded content aborts mid-stream: headers and initial bytes arrive but the body terminates early — an aborted chunked transfer is the only truncation signal for encoded content. Content-MD5 is emitted only for identity-stored content; validate against it when present.

Path parameters

  • artifact_id: string

The Artifact ID (tagged ID, e.g., cart_abc123)

  • version_id: string

Opaque version identifier from the Artifact's versions list

Headers

  • "x-api-key": optional string

Example

bash
curl https://haijun.my.id/v1/compliance/apps/code/artifacts/$ARTIFACT_ID/versions/$VERSION_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"

Delete Code Artifact

DELETE /v1/compliance/apps/code/artifacts/{artifact_id}

Permanently deletes a Code Artifact and all its versions. This is a destructive operation that cannot be undone. A 200 response means the deletion is initiated and the Artifact is claimed; content removal completes asynchronously.

Returns 404 for Artifacts that don't exist or belong to another parent organization. Returns 404 on a repeated delete of an already-deleted Artifact.

Path parameters

  • artifact_id: string

The Artifact ID (tagged ID, e.g., cart_abc123)

Headers

  • "x-api-key": optional string

Returns

  • type: "code_artifact_deleted"

Constant string confirming deletion

default: code_artifact_deleted

  • id: string

The ID of the Artifact that was deleted

Example

bash
curl https://haijun.my.id/v1/compliance/apps/code/artifacts/$ARTIFACT_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"
Response (200)
json
{
  "id": "cart_xyz789",
  "type": "code_artifact_deleted"
}
On this page
Compliance API › ActivitiesQuery compliance activitiesQuery parametersHeadersReturnsExampleCompliance API › OrganizationsList organizationsQuery parametersHeadersReturnsExampleCompliance API › Organizations › UsersList organization usersPath parametersQuery parametersHeadersReturnsExampleCompliance API › Organizations › RolesList Compliance RolesPath parametersQuery parametersHeadersReturnsExampleGet Compliance RolePath parametersHeadersReturnsExampleCompliance API › Organizations › Roles › PermissionsList Compliance Role PermissionsPath parametersQuery parametersHeadersReturnsExampleCompliance API › Organizations › SettingsGet effective organization settingsPath parametersHeadersReturnsExampleCompliance API › GroupsList Compliance GroupsQuery parametersHeadersReturnsExampleGet Compliance GroupPath parametersHeadersReturnsExampleCompliance API › Groups › MembersList Compliance Group MembersPath parametersQuery parametersHeadersReturnsExampleCompliance API › Apps › ChatsList chatsQuery parametersHeadersReturnsExampleDelete chatPath parametersHeadersReturnsExampleCompliance API › Apps › Chats › MessagesGet chat messagesPath parametersQuery parametersHeadersReturnsExampleCompliance API › Apps › Chats › FilesGet file metadataPath parametersHeadersReturnsExampleDelete filePath parametersHeadersReturnsExampleDownload file contentPath parametersHeadersExampleCompliance API › Apps › Chats › Generated FilesGet Haijun-generated file metadataPath parametersHeadersReturnsExampleDownload a Haijun-generated filePath parametersHeadersExampleCompliance API › Apps › ProjectsList projectsQuery parametersHeadersReturnsExampleGet project detailsPath parametersHeadersReturnsExampleDelete projectPath parametersHeadersReturnsExampleCompliance API › Apps › Projects › AttachmentsList project attachmentsPath parametersQuery parametersHeadersReturnsExampleCompliance API › Apps › Projects › CollaboratorsList project collaboratorsPath parametersQuery parametersHeadersReturnsExampleCompliance API › Apps › Projects › DocumentsGet project document contentPath parametersHeadersReturnsExampleGet project document metadataPath parametersHeadersReturnsExampleDelete project documentPath parametersHeadersReturnsExampleCompliance API › Apps › ArtifactsGet artifact metadataPath parametersHeadersReturnsExampleDownload artifact contentPath parametersHeadersExampleCompliance API › Apps › Sessions › LocalList local sessionsQuery parametersHeadersReturnsExampleRetrieve a local sessionPath parametersHeadersReturnsExampleCompliance API › Apps › Sessions › Local › MessagesRetrieve local session messagesPath parametersQuery parametersHeadersReturnsExampleCompliance API › Apps › Sessions › RemoteList remote sessionsQuery parametersHeadersReturnsExampleCompliance API › Apps › Sessions › Remote › MessagesRetrieve remote session messagesPath parametersQuery parametersHeadersReturnsExampleCompliance API › Code › ArtifactsList Code ArtifactsQuery parametersHeadersReturnsExampleDownload Code Artifact Version ContentPath parametersHeadersExampleDelete Code ArtifactPath parametersHeadersReturnsExample