GET /v1/compliance/activities
List compliance activities for the authenticated tenant.
The tenant is the caller's parent organization, or — for an organization with no parent — the organization itself. Returns a paginated list of compliance activities that can be filtered by various criteria.
Query parameters
activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more
Filter activities by type. See the response data schema for the additional fields each type returns. Cannot be combined with exclude_activity_types[].
"abuse_decision_received"
An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.
"account_deleted"
User-initiated self-service account deletion.
"admin_api_key_created"
An admin API key was created.
"admin_api_key_deleted"
An admin API key was deleted.
"admin_api_key_updated"
An admin API key was updated (renamed or activated/deactivated).
"admin_connector_request_resolved"
Admin approved or dismissed pending member requests to enable an MCP connector.
"admin_request_created"
Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).
"admin_setup_checklist_step_delegated"
A step of the Haijun Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.
"admin_setup_checklist_step_delegation_cancelled"
The delegation of a Haijun Enterprise admin setup checklist step was cancelled.
"age_verified"
User age was verified.
"anonymous_mobile_login_attempted"
Anonymous mobile login was attempted.
"api_key_created"
Activity logged when a new API key is created.
"audit_log_export_accessed"
Audit log export file was accessed/downloaded via signed URL.
"audit_log_export_started"
Audit log export was initiated.
"billing_emails_updated"
The organization's billing email recipients were updated.
"ccr_agent_created"
A Haijun Code agent was created.
"ccr_agent_deleted"
A Haijun Code agent was deleted.
"ccr_agent_proxy_juglow_oidc_token_exchanged"
The Haijun Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.
"ccr_agent_proxy_juglow_oidc_token_minted"
The Haijun Code agent proxy minted a short-lived identity token for an juglow_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.
"ccr_agent_proxy_credential_created"
A Haijun Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Haijun Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.
"ccr_agent_proxy_credential_deleted"
A Haijun Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.
"ccr_agent_proxy_credential_rotated"
A Haijun Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.
"ccr_agent_proxy_credential_updated"
A Haijun Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.
"ccr_agent_proxy_destination_deleted"
An agent proxy destination was deleted.
"ccr_agent_proxy_network_events_listed"
A Haijun Code network activity export was accessed for the given hour.
"ccr_agent_proxy_profile_bound"
A Haijun Code agent proxy profile was bound to a scope, applying its policy to Haijun Code sessions in that scope.
"ccr_agent_proxy_profile_created"
A Haijun Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.
"ccr_agent_proxy_profile_deleted"
A Haijun Code agent proxy profile was deleted, removing its policy from everything it was bound to.
"ccr_agent_proxy_profile_unbound"
A Haijun Code agent proxy profile was unbound from a scope, removing its policy from Haijun Code sessions in that scope.
"ccr_agent_proxy_profile_updated"
A Haijun Code agent proxy profile's configuration was updated.
"ccr_agent_proxy_provisioning_credential_rejected"
An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.
"ccr_agent_proxy_provisioning_link_enabled"
An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.
"ccr_agent_proxy_provisioning_link_generated"
An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.
"ccr_agent_proxy_provisioning_link_revoked"
An organization owner revoked an unfilled agent proxy provisioning link.
"ccr_agent_proxy_provisioning_link_submitted"
A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.
"ccr_agent_proxy_rule_created"
An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.
"ccr_agent_proxy_rule_deleted"
An agent proxy rule was deleted.
"ccr_agent_proxy_rule_updated"
An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.
"ccr_agent_slack_access_scope_created"
A Haijun Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.
"ccr_agent_slack_access_scope_deleted"
A Haijun Code agent's access to an additional Slack channel was revoked.
"ccr_agent_slack_binding_created"
A Haijun Code agent was assigned to a Slack channel or workspace as its dedicated agent.
"ccr_agent_slack_binding_deleted"
A Haijun Code agent's assignment to a Slack channel or workspace was removed.
"ccr_agent_updated"
A Haijun Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.
"ccr_channel_manager_added"
An org owner/admin assigned an organization member to manage the Haijun-in-Slack configuration of one Slack channel.
"ccr_channel_manager_removed"
An org owner/admin removed an organization member's assignment to manage the Haijun-in-Slack configuration of one Slack channel.
"ccr_role_channel_assignment_deleted"
CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).
"ccr_role_channel_assignment_updated"
CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Haijun-in-Slack channel-manage surface.
"ccr_session_created"
A Haijun Code session was created. A session is one coding interaction with Haijun.
"ccr_session_deleted"
A Haijun Code session was deleted.
"ccr_session_updated"
A Haijun Code session's settings were updated.
"ccr_slack_channel_joined"
Haijun's Slack app joined a public Slack channel at an organization administrator's request.
"haijun_artifact_access_failed"
An attempt to access an artifact failed.
"haijun_artifact_commented"
Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.
"haijun_artifact_comments_viewed"
An artifact's comments were viewed.
"haijun_artifact_created"
An artifact was created.
"haijun_artifact_duplicated"
A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.
"haijun_artifact_external_sharing_permission_updated"
An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
"haijun_artifact_invite_accepted"
Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by invitee_email and invitee_user_id.
"haijun_artifact_invite_created"
A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
"haijun_artifact_invite_revoked"
A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
"haijun_artifact_invite_role_updated"
A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
"haijun_artifact_published"
A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as haijun_artifact_sharing_updated.
"haijun_artifact_sharing_updated"
An artifact's sharing settings were updated.
"haijun_artifact_viewed"
An artifact was viewed.
"haijun_chat_access_failed"
A user was denied access to a Haijun.ai chat conversation.
"haijun_chat_created"
User created a chat.
"haijun_chat_deleted"
A user deleted a Haijun.ai chat conversation.
"haijun_chat_deletion_failed"
A request to delete a Haijun.ai chat conversation failed.
"haijun_chat_settings_updated"
User updated the settings for a conversation.
"haijun_chat_snapshot_created"
User created/shared a chat snapshot.
"haijun_chat_snapshot_deleted"
User deleted/unshared a chat snapshot.
"haijun_chat_snapshot_viewed"
User viewed a chat snapshot (authenticated or public/unauthenticated).
"haijun_chat_sync_source_created"
A sync source was connected for syncing external content into Haijun chats.
"haijun_chat_sync_source_deleted"
A sync source was disconnected from Haijun chats.
"haijun_chat_sync_source_updated"
A Haijun chat sync source's configuration was updated.
"haijun_chat_updated"
User updated the chat metadata (e.g name, model).
"haijun_chat_viewed"
A user viewed a Haijun.ai chat conversation.
"haijun_code_credential_revoked"
A Haijun Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.
"haijun_code_review_config_updated"
Haijun Code Review configuration was enabled/disabled for an org.
"haijun_code_review_repository_added"
A repository was added to org-level Haijun Code Review configuration.
"haijun_code_review_repository_removed"
A repository was removed from org-level Haijun Code Review configuration.
"haijun_code_review_repository_updated"
A Haijun Code Review repository configuration was updated.
"haijun_code_runner_deleted"
A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.
"haijun_code_runner_pool_created"
A self-hosted runner pool for Haijun Code was created.
"haijun_code_runner_pool_deleted"
A self-hosted runner pool was deleted.
"haijun_code_runner_pool_secret_minted"
A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.
"haijun_code_runner_pool_session_queue_updated"
An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.
"haijun_code_runner_pool_updated"
A self-hosted runner pool's settings were updated.
"haijun_code_security_center_config_updated"
Haijun Code Security Center scanning was enabled/disabled for an org.
"haijun_code_security_scan_cancelled"
In-flight Haijun Code Security scans were cancelled for a project.
"haijun_code_security_scan_created"
A Haijun Code Security scan was started.
"haijun_code_security_scan_project_member_updated"
A person's access to a Haijun Code Security scan project was granted, changed, or revoked.
"haijun_code_security_scan_project_updated"
A Haijun Code Security scan project was archived, unarchived, created, or migrated to a new product experience.
"haijun_code_security_scan_project_visibility_updated"
A Haijun Code Security scan project was shared with the organization or made private.
"haijun_code_security_scan_run_updated"
A single Haijun Code Security scan run was archived, unarchived, or resumed after a billing pause.
"haijun_code_security_scan_schedule_deleted"
A recurring scan schedule was deleted for a Haijun Code Security project.
"haijun_code_security_scan_schedule_updated"
A recurring scan schedule was set or replaced for a Haijun Code Security project.
"haijun_code_security_vulnerability_deleted"
A Haijun Code Security vulnerability finding was permanently deleted.
"haijun_code_security_vulnerability_fix_session_created"
A Haijun Code remediation session was created for a Haijun Code Security vulnerability finding.
"haijun_code_security_vulnerability_updated"
A Haijun Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.
"haijun_code_security_webhook_created"
A Haijun Code Security outbound webhook was created.
"haijun_code_security_webhook_deleted"
A Haijun Code Security outbound webhook was deleted.
"haijun_code_security_webhook_secret_updated"
The HMAC signing secret for a Haijun Code Security webhook was rotated.
"haijun_code_security_webhook_updated"
A Haijun Code Security outbound webhook was updated.
"haijun_code_team_memory_acl_updated"
An RBAC group was added to or removed from the Haijun Code team-memory ACL.
"haijun_code_team_memory_updated"
Haijun Code team memory shared with the organization was updated.
"haijun_code_team_onboarding_guide_updated"
A Haijun Code team onboarding guide was created, updated, or deleted.
"haijun_code_user_marketplaces_updated"
A user's Haijun Code plugin marketplace selections were updated on Juglow servers.
"haijun_code_user_memory_updated"
A user's synced private Haijun Code memory was updated or deleted on Juglow servers.
"haijun_code_user_plugins_updated"
A user's Haijun Code plugin selections — which plugins are installed and enabled — were updated on Juglow servers.
"haijun_code_user_settings_updated"
A user's synced Haijun Code settings were updated or deleted on Juglow servers.
"haijun_command_created"
Command was created.
"haijun_command_deleted"
Command was deleted.
"haijun_command_replaced"
Command was replaced.
"haijun_enterprise_upgrade_credit_updated"
An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.
"haijun_file_access_failed"
A user was denied access to a file in Haijun.ai.
"haijun_file_deleted"
A file was deleted.
"haijun_file_exported"
A file was exported from Haijun to an external storage destination.
"haijun_file_uploaded"
A file was uploaded.
"haijun_file_viewed"
A user viewed a file in Haijun.ai.
"haijun_gdrive_integration_created"
A Google Drive integration was enabled for the organization.
"haijun_gdrive_integration_deleted"
A Google Drive integration was disabled for the organization.
"haijun_gdrive_integration_updated"
A Google Drive integration's configuration was updated.
"haijun_github_integration_created"
A GitHub integration was enabled for the organization.
"haijun_github_integration_deleted"
A GitHub integration was disabled for the organization.
"haijun_github_integration_updated"
A GitHub integration's configuration was updated.
"haijun_organization_settings_updated"
Organization settings were updated.
"haijun_plugin_archive_accessed"
A version archive of a member-owned plugin, containing that member's own files, was downloaded.
"haijun_plugin_created"
Plugin was created.
"haijun_plugin_deleted"
Plugin was deleted.
"haijun_plugin_disabled"
User disabled a plugin for their account.
"haijun_plugin_enabled"
User enabled a plugin for their account.
"haijun_plugin_replaced"
Plugin was replaced.
"haijun_plugin_security_scan_completed"
A security scan of a plugin completed and produced a verdict.
"haijun_plugin_updated"
Plugin was updated.
"haijun_project_archived"
A Haijun project was archived.
"haijun_project_created"
A Haijun project was created.
"haijun_project_deleted"
A Haijun project was deleted.
"haijun_project_document_access_failed"
An attempt to access a document in a Haijun project failed.
"haijun_project_document_bulk_deletion_audit_truncated"
A bulk request to delete documents from a Haijun project failed with more documents requested than were individually recorded in the audit log.
"haijun_project_document_deleted"
A document was deleted from a Haijun project.
"haijun_project_document_deletion_failed"
A request to delete a document from a Haijun project failed.
"haijun_project_document_updated"
The content of a document in a Haijun project was replaced in place.
"haijun_project_document_uploaded"
A document was uploaded to a Haijun project.
"haijun_project_document_viewed"
A document in a Haijun project was viewed.
"haijun_project_file_access_failed"
An attempt to access a file in a Haijun project failed.
"haijun_project_file_bulk_deletion_audit_truncated"
A bulk request to delete files from a Haijun project failed with more files requested than were individually recorded in the audit log.
"haijun_project_file_deleted"
A file was deleted from a Haijun project.
"haijun_project_file_deletion_failed"
A request to delete a file from a Haijun project failed.
"haijun_project_file_uploaded"
A file was uploaded to a Haijun project.
"haijun_project_reported"
A Haijun project was reported.
"haijun_project_sharing_updated"
A Haijun project's sharing settings were updated.
"haijun_project_sync_source_created"
A sync source was connected to a Haijun project's knowledge base.
"haijun_project_sync_source_deleted"
A sync source was disconnected from a Haijun project's knowledge base.
"haijun_project_sync_source_updated"
A Haijun project sync source's configuration was updated.
"haijun_project_viewed"
A Haijun project was viewed.
"haijun_published_artifact_deleted"
A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Juglow (for example, when it was removed for a policy violation).
"haijun_pubsec_identity_configured"
SAML IdP configuration updated for a public sector organization.
"haijun_skill_created"
Track was created.
"haijun_skill_deleted"
Track was deleted.
"haijun_skill_disabled"
User disabled a track for their account.
"haijun_skill_enabled"
User enabled a track for their account.
"haijun_skill_replaced"
Track was replaced.
"haijun_skill_security_scan_completed"
A security scan of a track completed and produced a verdict.
"haijun_user_role_updated"
A user's role within the organization was changed, or the user was added to or removed from the organization.
"haijun_user_seat_tier_updated"
An organization member's seat tier was changed. A null previous_seat_tier means the member previously had no seat assigned; a null current_seat_tier means the seat was removed.
"haijun_user_settings_updated"
User updated their personal settings.
"cli_plugin_exec_policy_updated"
Admin set or cleared the per-op permission ceiling for a plugin CLI.
"compliance_api_accessed"
Logging event auto-generated for each compliance API request.
"cowork_session_updated"
A Cowork session was updated.
"design_project_artifact_published"
A Haijun Design project's content was published as a haijun.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.
"design_project_created"
A Haijun Design project was created.
"design_project_deleted"
A Haijun Design project was deleted.
"design_project_member_added"
A member was granted access to a Haijun Design project.
"design_project_member_removed"
A member's access to a Haijun Design project was revoked.
"design_project_member_role_updated"
A Haijun Design project member's role was changed.
"design_project_published"
A Haijun Design template or design system was published, making it discoverable by everyone in its organization.
"design_project_sharing_updated"
A Haijun Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).
"design_project_unpublished"
A Haijun Design template or design system was unpublished, removing it from its organization's shared gallery.
"design_project_updated"
A Haijun Design project's metadata was updated.
"design_project_version_restored"
A Haijun Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.
"design_project_viewed"
A Haijun Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.
This activity type is retired: project content reads are no longer recorded. Events of this type may still appear in feeds for reads that occurred while it was active.
"desktop_extension_allowlisted"
A desktop extension was added to an org's allowlist.
"desktop_extension_blocklisted"
A desktop extension was added to the global blocklist.
"desktop_extension_deleted"
A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.
"desktop_extension_removed_from_allowlist"
A desktop extension was removed from an org's allowlist.
"desktop_extension_unblocked"
A desktop extension was removed from the global blocklist.
"desktop_extension_uploaded"
A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.
"desktop_extension_version_uploaded"
A new version of an existing org-owned desktop extension was uploaded.
"domain_claim_initiated"
Domain capture claim initiated over personal accounts on verified domains.
"end_user_invite_requested"
Non-admin member submitted an invite request for a new org member.
"extra_usage_billing_enabled"
Usage credit billing was enabled for an organization.
"extra_usage_credit_granted"
A promotional usage credit grant was claimed.
"extra_usage_spend_limit_created"
Usage credit spend limit was created.
"extra_usage_spend_limit_deleted"
Usage credit spend limit was deleted.
"extra_usage_spend_limit_increase_request_approved"
A usage credit spend limit increase request was approved.
"extra_usage_spend_limit_increase_request_denied"
A usage credit spend limit increase request was denied.
"extra_usage_spend_limit_updated"
Usage credit spend limit was updated.
"ghe_configuration_created"
Admin created a GHE configuration.
"ghe_configuration_deleted"
Admin deleted a GHE configuration.
"ghe_configuration_updated"
Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
"ghe_user_connected"
User connected to a GHE instance.
"ghe_user_disconnected"
User disconnected from a GHE instance.
"ghe_webhook_signature_invalid"
Webhook signature validation failed.
"github_app_installation_linked"
An installation of the Haijun GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Haijun Code features act on that GitHub account's repositories.
"github_app_installation_unlinked"
An installation of the Haijun GitHub App was unlinked from the organization, so the organization's Haijun Code features can no longer act on that GitHub account's repositories through it.
"github_token_import"
A user attempted to import a personal GitHub access token for use with Haijun Code. The result field indicates the outcome of the import (imported, rejected, or failed).
"gitlab_configuration_created"
An organization admin created a self-managed GitLab configuration for syncing plugin marketplaces.
"gitlab_configuration_deleted"
An organization admin deleted a self-managed GitLab configuration.
"gitlab_configuration_updated"
An organization admin updated a self-managed GitLab configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
"group_created"
A group was created (RBAC admin or SCIM provisioning).
"group_deleted"
A group was deleted (RBAC admin or SCIM provisioning).
"group_list_viewed"
Admin viewed the list of RBAC groups.
"group_member_added"
One or more members were added to a group.
"group_member_addition_failed"
A request to add members to a group failed. Some of the requested members may have been added before the failure.
"group_member_list_viewed"
Admin viewed the members of an RBAC group.
"group_member_removal_failed"
A request to remove members from a group failed. Some of the requested members may have been removed before the failure.
"group_member_removed"
One or more members were removed from a group.
"group_project_shares_revoked"
An RBAC group's project shares in one organization were revoked in bulk.
"group_skill_shares_revoked"
An RBAC group's track shares in one organization were revoked in bulk.
"group_updated"
A group was updated (RBAC admin or SCIM provisioning).
"group_viewed"
A group was viewed.
"group_visibility_updated"
An RBAC group's visibility policy was updated.
"inference_hooks_circuit_breaker_tripped"
The organization's Inference hooks circuit breaker tripped automatically: calls to the organization's Inference hooks endpoint crossed a failure threshold, and inspection was suspended to protect live traffic. While tripped, requests are handled according to the organization's failure handling setting — allowed through uninspected (fail open) or rejected (fail closed) — and no per-request Inference hooks activities are recorded. The tripped state persists until an administrator re-enables Inference hooks inspection (or explicitly resets the circuit breaker).
"inference_hooks_config_deleted"
Inference hooks configuration was removed for the organization.
"inference_hooks_config_updated"
Inference hooks configuration was created or updated for the organization.
"inference_hooks_request_denied"
Inference hooks inspection denied a request. The request was blocked and no model response was produced.
"inference_hooks_request_failed_open"
A request proceeded without Inference hooks inspection because a verdict could not be obtained and the organization's Inference hooks configuration is set to fail open.
"inference_hooks_signing_secret_generated"
A request signing secret was generated for the organization's Inference hooks configuration.
"integration_user_connected"
User connected to an integration.
"integration_user_disconnected"
User disconnected from an integration.
"invoice_collection_method_updated"
Invoice collection method was changed.
"lti_launch_initiated"
LTI launch was initiated.
"lti_launch_success"
LTI launch completed successfully.
"lti_platform_created"
Juglow staff created an LTI platform integration on behalf of an org.
"lti_platform_updated"
Juglow staff updated an LTI platform integration on behalf of an org.
"magic_link_login_failed"
A magic link sign-in attempt failed.
"magic_link_login_initiated"
A user requested a magic link sign-in email.
"magic_link_login_succeeded"
A user successfully signed in with a magic link email.
"managed_organization_setup_completed"
Managed (AWS Marketplace) organization setup was completed.
"marketplace_created"
Admin created an organization marketplace.
"marketplace_deleted"
Admin deleted an organization marketplace.
"marketplace_updated"
Admin updated an organization marketplace.
"marketplace_webhook_deleted"
Admin removed the GitHub push webhook for a marketplace.
"marketplace_webhook_provisioned"
Admin provisioned a GitHub push webhook for a marketplace.
"mcp_directory_server_published"
The organization published its approved MCP directory listing.
"mcp_server_created"
An MCP server was added to the organization.
"mcp_server_deleted"
An MCP server was removed from the organization.
"mcp_server_managed_auth_token_exchanged"
A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
"mcp_server_managed_auth_updated"
An MCP server's enterprise managed authorization settings were set, changed, or cleared, including when they were supplied while the server was being added or edited. Fields without a "previous_" prefix describe the settings after the change and are null when the server has no managed authorization settings afterwards; "previous_" fields describe the settings before the change and are null when the server had none before (always the case for a newly added server).
"mcp_server_updated"
An MCP server's configuration was updated.
"mcp_tool_policy_updated"
The permission restriction for an MCP tool was set or cleared.
"org_analytics_api_capability_updated"
Organization analytics_api capability was enabled or disabled.
"org_bulk_delete_initiated"
Organization bulk deletion was initiated.
"org_capability_grant_added"
A capability grant was added to a workspace or role.
"org_capability_grant_removed"
A capability grant was removed from a workspace or role.
"org_haijun_code_data_sharing_disabled"
Organization Haijun Code data sharing was disabled.
"org_haijun_code_data_sharing_enabled"
Organization Haijun Code data sharing was enabled.
"org_haijun_code_desktop_disabled"
Organization Haijun Code Desktop was disabled.
"org_haijun_code_desktop_enabled"
Organization Haijun Code Desktop was enabled.
"org_haijun_code_zero_data_retention_disabled"
A primary owner disabled zero data retention for Haijun Code, so Haijun Code content is retained according to the organization's data retention settings.
"org_compliance_api_settings_updated"
Organization compliance API settings were updated.
"org_connector_domain_guard_updated"
Enterprise admin changed whether connectors are restricted to verified domains.
"org_cowork_act_without_asking_mode_disabled"
The "Act without asking" mode in Cowork was disabled for the organization, so members can no longer let Haijun act without asking for approval.
"org_cowork_act_without_asking_mode_enabled"
The "Act without asking" mode in Cowork was enabled for the organization, allowing members to let Haijun act without asking for approval.
"org_cowork_agent_disabled"
Organization Cowork Agent was disabled.
"org_cowork_agent_enabled"
Organization Cowork Agent was enabled.
"org_cowork_auto_mode_disabled"
The "Auto" permission mode in Cowork was disabled for the organization, so members can no longer let Haijun approve its own actions after a safety check.
"org_cowork_auto_mode_enabled"
The "Auto" permission mode in Cowork was enabled for the organization, allowing members to let Haijun approve its own actions after a safety check.
"org_cowork_browser_pane_disabled"
The in-app browser in Cowork was disabled for the organization, so Haijun can no longer open or use websites in a browser pane during members' Cowork sessions.
"org_cowork_browser_pane_enabled"
The in-app browser in Cowork was enabled for the organization, letting Haijun open and use websites in a browser pane during members' Cowork sessions.
"org_cowork_disabled"
Organization cowork was disabled.
"org_cowork_enabled"
Organization cowork was enabled.
"org_cowork_mcp_always_allow_disabled"
The "Always allow" option for connector tools in Cowork was disabled for the organization, so each use of a connector tool that can make changes requires approval. Read-only connector tools are not affected by this setting.
"org_cowork_mcp_always_allow_enabled"
The "Always allow" option for connector tools in Cowork was enabled for the organization, letting members approve a connector tool that can make changes once and allow its later uses automatically. Read-only connector tools are not affected by this setting.
"org_cowork_otlp_settings_updated"
The organization's Cowork OpenTelemetry monitoring export settings were updated.
"org_cowork_remote_disabled"
Running Cowork in the cloud was disabled for the organization, so members can no longer run Cowork sessions in Juglow-hosted remote environments.
"org_cowork_remote_enabled"
Running Cowork in the cloud was enabled for the organization, allowing members to run Cowork sessions in Juglow-hosted remote environments.
"org_creation_blocked"
Organization creation was blocked.
"org_data_export_accessed"
Organization data export file was accessed/downloaded via signed URL.
"org_data_export_completed"
Organization data export was completed.
"org_data_export_started"
Organization data export was started.
"org_data_residency_updated"
The organization's inference data residency settings were updated.
"org_deleted_via_bulk"
Organization was deleted via bulk operation.
"org_deletion_requested"
Organization deletion was requested.
"org_directory_resync_completed"
Organization directory resync completed successfully.
"org_directory_resync_failed"
Organization directory resync failed.
"org_directory_resync_started"
Organization directory resync was started asynchronously.
"org_directory_sync_activated"
Organization directory sync was activated.
"org_directory_sync_add_initiated"
Organization directory sync setup was initiated.
"org_directory_sync_deleted"
Organization directory sync was deleted.
"org_discoverability_disabled"
Admin disabled organization discoverability.
"org_discoverability_enabled"
Admin enabled organization discoverability.
"org_discoverability_settings_updated"
Admin updated organization discoverability settings.
"org_domain_add_initiated"
Organization domain verification was initiated.
"org_domain_removed"
Organization domain was removed.
"org_domain_verified"
Organization domain was verified.
"org_external_key_created"
A CMEK external key config was created.
"org_external_key_deleted"
A CMEK external key config was deleted.
"org_external_key_updated"
A CMEK external key config was updated.
"org_external_key_validated"
A CMEK external key config was validated against the customer's KMS.
"org_hipaa_self_serve_enabled"
A primary owner click-accepted the BAA and enabled HIPAA protections for the organization via the self-serve flow.
"org_invite_link_disabled"
Organization invite link was disabled.
"org_invite_link_generated"
Organization invite link was generated.
"org_invite_link_regenerated"
Organization invite link was regenerated (previous link invalidated).
"org_invite_viewed"
An organization invite was viewed.
"org_invites_listed"
Organization invites were listed.
"org_ip_restriction_created"
Organization IP restriction was created.
"org_ip_restriction_deleted"
Organization IP restriction was deleted.
"org_ip_restriction_updated"
Organization IP restriction was updated.
"org_join_proposal_decided"
Approve or reject decision on a parent-org join proposal.
"org_join_request_approved"
Admin approved a join request.
"org_join_request_created"
User requested to join an organization.
"org_join_request_dismissed"
Admin dismissed a join request.
"org_join_request_instant_approved"
Join request was instantly approved.
"org_join_requests_bulk_dismissed"
Admin bulk-dismissed join requests.
"org_magic_link_second_factor_toggled"
Organization magic link second factor was toggled.
"org_member_invites_disabled"
Admin disabled member invites for the organization.
"org_member_invites_enabled"
Admin enabled member invites for the organization.
"org_members_exported"
Organization members list was exported as CSV.
"org_model_default_updated"
An organization or role default model setting was changed by an administrator.
"org_parent_join_proposal_created"
Organization parent join proposal was created.
"org_parent_search_performed"
Organization parent search was performed.
"org_sso_add_initiated"
Organization SSO setup was initiated.
"org_sso_connection_activated"
Organization SSO connection was activated.
"org_sso_connection_deactivated"
Organization SSO connection was deactivated.
"org_sso_connection_deleted"
Organization SSO connection was deleted.
"org_sso_group_role_mappings_updated"
Organization SSO group role mappings were updated.
"org_sso_provisioning_mode_changed"
Organization SSO provisioning mode was changed.
"org_sso_scim_welcome_email_toggled"
Organization SCIM-provisioned welcome email was toggled.
"org_sso_seat_tier_assignment_toggled"
Organization SSO seat tier assignment was toggled.
"org_sso_seat_tier_mappings_updated"
Organization SSO seat tier mappings were updated.
"org_sso_toggled"
Organization SSO was toggled on or off.
"org_sync_deleting_synchronized_files_started"
Organization started deleting synchronized files.
"org_sync_synchronized_files_deleted"
Organization synchronized files were deleted.
"org_taint_added"
A taint was added to an organization.
"org_taint_removed"
A taint was removed from an organization.
"org_user_deleted"
User was removed from organization.
"org_user_invite_accepted"
Organization user invite was accepted.
"org_user_invite_deleted"
Organization user invite was deleted.
"org_user_invite_re_sent"
Organization user invite was re-sent.
"org_user_invite_rejected"
Organization user invite was rejected.
"org_user_invite_sent"
Organization user invite was sent.
"org_user_left"
User removed themselves from organization.
"org_user_shares_retained"
A member left or was removed from the organization while projects, tracks, plugins, or chats they had shared were still shared, and those shares were kept.
"org_user_trusted_devices_revoked"
An organization admin revoked a member's trusted devices and signed the member out of all active sessions.
"org_user_viewed"
An organization user was viewed.
"org_users_listed"
Organization users were listed.
"org_work_across_apps_disabled"
The organization's "Let Haijun work across apps" setting was turned off.
"org_work_across_apps_enabled"
The organization's "Let Haijun work across apps" setting was turned on.
"organization_address_updated"
The organization's billing or shipping address was updated.
"organization_icon_deleted"
Organization's custom icon deleted.
"organization_icon_updated"
Organization's custom icon uploaded or replaced.
"owned_projects_access_restored"
Access to owned projects was restored.
"payment_method_updated"
The organization's default payment method was updated.
"pending_share_created"
A pending share of a project or track was created for an email address that is not yet an organization member.
"pending_share_revoked"
A pending share of a project or track was revoked before the invitee joined the organization.
"phone_code_sent"
User requested a phone verification code.
"phone_code_verified"
User successfully verified their phone code.
"platform_agent_archived"
An agent was archived on the API platform.
"platform_agent_created"
An agent was created on the API platform.
"platform_agent_deleted"
An agent was deleted from the API platform.
"platform_agent_deployment_archived"
An agent deployment was archived on the API platform.
"platform_agent_deployment_created"
An agent deployment was created on the API platform.
"platform_agent_deployment_deleted"
An agent deployment was deleted from the API platform.
"platform_agent_deployment_paused"
An agent deployment was paused on the API platform.
"platform_agent_deployment_run_triggered"
An agent deployment was run on demand on the API platform.
"platform_agent_deployment_unpaused"
An agent deployment was resumed on the API platform.
"platform_agent_deployment_updated"
An agent deployment was updated on the API platform.
"platform_agent_session_archived"
An agent session was archived on the API platform.
"platform_agent_session_created"
An agent session was created on the API platform.
"platform_agent_session_deleted"
An agent session was deleted from the API platform.
"platform_agent_session_resource_added"
A resource was attached to an agent session.
"platform_agent_session_resource_deleted"
A resource attached to an agent session was removed.
"platform_agent_session_resource_updated"
A resource attached to an agent session was updated.
"platform_agent_session_thread_archived"
A thread within an agent session was archived.
"platform_agent_session_updated"
An agent session was updated on the API platform.
"platform_agent_updated"
An agent was updated on the API platform.
"platform_api_key_created"
An API key was created.
"platform_api_key_updated"
An API key was updated.
"platform_app_attest_authentication"
An attested mobile device attempted to exchange an Apple App Attest assertion for Juglow API credentials.
"platform_billing_upgraded_to_prepaid"
The organization's API billing was upgraded to the prepaid plan.
"platform_clearance_workspace_program_request_cleared"
A workspace's clearance program assignment was removed.
"platform_clearance_workspace_program_request_set"
A workspace's clearance program assignment was created or updated.
"platform_cost_report_viewed"
The cost report was viewed.
"platform_dream_archived"
A Dream (asynchronous memory-consolidation job) was archived.
"platform_dream_cancelled"
A Dream (asynchronous memory-consolidation job) was cancelled before it completed.
"platform_dream_created"
A Dream (asynchronous memory-consolidation job) was created.
"platform_federated_authentication"
A federated workload identity attempted to exchange an OIDC token for Juglow API credentials.
"platform_federation_issuer_archived"
An OIDC federation issuer was archived.
"platform_federation_issuer_created"
An OIDC federation issuer was created, registering an external identity provider that federation rules can trust for workload authentication.
"platform_federation_issuer_updated"
An OIDC federation issuer was updated.
"platform_federation_rule_archived"
An OIDC federation rule was archived.
"platform_federation_rule_created"
An OIDC federation rule was created, allowing tokens from a federation issuer to authenticate as a service account or user. Rules may additionally match on token claims or a condition expression, which are not included in this event.
"platform_federation_rule_updated"
An OIDC federation rule was updated.
"platform_federation_rule_workspace_added"
A federation rule was enabled for a workspace.
"platform_federation_rule_workspace_removed"
A federation rule was disabled for a workspace.
"platform_file_content_downloaded"
Activity logged when file content is downloaded via GET /v1/files/{file_id}/content.
"platform_file_deleted"
Activity logged when a file is deleted via DELETE /v1/files/{file_id}.
"platform_file_uploaded"
Activity logged when a file is uploaded via POST /v1/files.
"platform_memory_created"
An agent memory document was created.
"platform_memory_deleted"
An agent memory document was deleted.
"platform_memory_store_archived"
An agent memory store was archived. Archived stores reject new memory writes and cannot be attached to new sessions; deletion and redaction remain permitted for privacy scrubbing.
"platform_memory_store_created"
An agent memory store was created.
"platform_memory_store_deleted"
An agent memory store was deleted. Memory content removal may complete asynchronously for very large stores.
"platform_memory_store_updated"
An agent memory store's name, description, or metadata was updated.
"platform_memory_updated"
An agent memory document's content or path was updated.
"platform_memory_version_redacted"
A historical version of an agent memory document was redacted. Redaction scrubs the stored content of a specific version while preserving the version's existence in the history.
"platform_oauth_app_created"
An OAuth app was created.
"platform_oauth_app_revoked"
An OAuth app was revoked.
"platform_oauth_app_updated"
An OAuth app was updated.
"platform_plugin_directory_submission_created"
A plugin directory submission was created on the API platform. A plugin directory submission is a request to list a plugin in the public plugin directory.
"platform_plugin_directory_submission_deleted"
A plugin directory submission was deleted on the API platform.
"platform_plugin_directory_submission_updated"
A plugin directory submission was updated on the API platform.
"platform_service_account_archived"
A service account was archived.
"platform_service_account_created"
A service account was created.
"platform_service_account_updated"
A service account was updated.
"platform_service_account_workspace_member_added"
A service account was added as a member of a workspace.
"platform_service_account_workspace_member_removed"
A service account was removed from a workspace.
"platform_service_account_workspace_member_updated"
A service account's workspace membership role was updated.
"platform_signing_key_created"
Activity logged when a new request-signing key is registered for the org.
"platform_signing_key_deleted"
Activity logged when a signing key is permanently deleted.
"platform_signing_key_rotated"
Activity logged when an in-memory signing key is rotated.
"platform_skill_version_content_downloaded"
The content of a track version was downloaded through the Tracks API.
"platform_skill_version_created"
Activity logged when a track version is created via POST /v1/tracks/{skill_id}/versions.
"platform_skill_version_deleted"
Activity logged when a track version is deleted via DELETE /v1/tracks/{skill_id}/versions/{version}.
"platform_spend_limit_alert_emails_updated"
Spend limit alert email addresses and role targets were updated for an org.
"platform_spend_limit_created"
An org-level fixed-dollar spend limit was created.
"platform_spend_limit_deleted"
An org-level spend limit was removed.
"platform_spend_limit_updated"
An org-level spend limit snooze/ignore state was changed.
"platform_usage_report_haijun_code_viewed"
The Haijun Code usage report was viewed.
"platform_usage_report_messages_viewed"
The messages usage report was viewed.
"platform_workspace_archived"
A workspace was archived.
"platform_workspace_created"
A workspace was created.
"platform_workspace_inference_data_retention_disabled"
The zero data retention override was disabled for a workspace.
"platform_workspace_inference_data_retention_enabled"
The zero data retention override was enabled for a workspace.
"platform_workspace_member_added"
A member was added to a workspace.
"platform_workspace_member_removed"
A member was removed from a workspace.
"platform_workspace_member_updated"
A workspace member was updated.
"platform_workspace_member_viewed"
A workspace member was viewed.
"platform_workspace_members_listed"
Workspace members were listed.
"platform_workspace_rate_limit_deleted"
A workspace rate limit was deleted.
"platform_workspace_rate_limit_updated"
A workspace rate limit was created or updated.
"platform_workspace_updated"
A workspace was updated.
"plugin_installation_preference_updated"
An org admin changed the installation preference for a plugin.
"prepaid_auto_recharge_disabled"
Auto-recharge was disabled for API prepaid org.
"prepaid_auto_recharge_updated"
Auto-recharge settings were updated for API prepaid org.
"prepaid_extra_usage_auto_reload_disabled"
Prepaid usage credit auto-reload was disabled.
"prepaid_extra_usage_auto_reload_enabled"
Prepaid usage credit auto-reload was enabled.
"prepaid_extra_usage_auto_reload_settings_updated"
Prepaid usage credit auto-reload settings were updated.
"primary_owner_transferred"
Primary owner role was transferred to another org member.
"rbac_role_assigned"
Admin assigned an RBAC custom role to a principal.
"rbac_role_created"
Admin created an RBAC custom role.
"rbac_role_deleted"
Admin deleted an RBAC custom role.
"rbac_role_grant_updated"
Admin requested a capability grant for an RBAC custom role, or removed it.
Records the admin's change to the role. Whether the grant is currently in effect on the role is reported separately.
"rbac_role_permission_added"
Admin added a permission to an RBAC custom role.
Emitted once per requested permission, including permissions the role already had, so a retried request still produces a complete audit record.
"rbac_role_permission_removed"
Admin removed a permission from an RBAC custom role.
Emitted once per requested permission, including permissions the role already lacked, so a retried request still produces a complete audit record.
"rbac_role_unassigned"
Admin unassigned an RBAC custom role from a principal.
"rbac_role_updated"
Admin updated an RBAC custom role.
"role_assignment_granted"
Role assignment was granted.
"role_assignment_revoked"
Role assignment was revoked.
"scim_user_created"
A SCIM user was provisioned.
"scim_user_deleted"
A SCIM user was deleted.
"scim_user_updated"
A SCIM user was updated.
"scoped_api_key_deleted"
A scoped API key was deleted.
"scoped_api_key_updated"
A scoped API key was renamed or its activation state changed.
"seat_tier_changes_cancelled"
Scheduled seat tier downgrades were cancelled.
"seat_tiers_purchased"
Seat tiers were purchased or upgraded on a subscription.
"service_created"
Activity logged when an org service is explicitly created.
"service_deleted"
Activity logged when an org service is deleted.
"service_key_created"
Activity logged when a new org service key is created.
"service_key_revoked"
Activity logged when an org service key is revoked.
"session_revoked"
User revoked a specific session.
"session_share_accessed"
Session share was accessed.
"session_share_created"
Session share was created.
"session_share_revoked"
Session share was revoked.
"slack_workspace_claim_revoked"
A Slack workspace or Enterprise Grid organization was disconnected from the organization for Haijun in Slack.
"slack_workspace_claimed"
A Slack workspace or Enterprise Grid organization was connected to the organization for Haijun in Slack.
"social_login_succeeded"
A user successfully signed in with a social identity provider (Google, Apple, or Microsoft).
"sso_login_failed"
An SSO sign-in attempt failed.
"sso_login_initiated"
A user started an SSO sign-in flow.
"sso_login_succeeded"
A user successfully signed in with SSO.
"sso_second_factor_magic_link"
SSO second factor magic link was used.
"step_up_authentication_failed"
An additional identity check failed.
"step_up_authentication_succeeded"
The user completed an additional identity check to confirm a sensitive action.
"step_up_credential_enrolled"
A user enrolled a passkey for confirming sensitive actions on their account.
"subscription_cancellation_scheduled"
Subscription cancellation was scheduled at end of billing period.
"subscription_quantity_updated"
Contracted subscription seat quantity was updated.
"subscription_renewed"
A cancelled subscription was renewed.
"subscription_resumed"
A scheduled subscription cancellation was reversed.
"subscription_started"
A new subscription was created (Team or Enterprise).
"subscription_upgraded"
Subscription plan was upgraded (e.g. Team to Enterprise).
"trusted_device_credential_rotated"
The identity-verification credential of a trusted device was rotated to a new key.
"trusted_device_enrolled"
A device was enrolled as a trusted device for the user's account. Trusted devices can be used to confirm the user's identity for sensitive actions.
"trusted_device_revoked"
A trusted device was removed from the user's account.
"tunnel_archived"
An MCP tunnel was archived.
"tunnel_certificate_added"
An inner-TLS CA certificate was added to a tunnel.
"tunnel_certificate_revoked"
An inner-TLS CA certificate was revoked from a tunnel.
"tunnel_created"
An MCP tunnel was created.
"tunnel_token_minted"
An OAuth bearer token for the tunnel management API was minted.
"tunnel_token_revealed"
The Cloudflare connector secret for a tunnel was revealed to the caller.
"tunnel_token_revoked"
An OAuth bearer token for the tunnel management API was revoked.
"tunnel_token_rotated"
The Cloudflare connector secret for a tunnel was rotated.
tunnel_token_id is the id of the newly-issued token. The previous token is invalidated by the rotation and its id is not recorded here.
"user_consent_recorded"
User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).
"user_consent_revoked"
User revoked a previously granted consent for a specific entity.
"user_logged_out"
A user signed out of one or all sessions.
"verification_evidence_submitted"
Verification evidence was submitted for an organization's verification.
"verification_program_application_created"
An organization applied to a verification program.
"workspace_member_spend_limit_created"
A per-member or workspace-default Haijun Code spend limit was created.
"workspace_member_spend_limit_deleted"
A per-member or workspace-default Haijun Code spend limit was deleted.
"workspace_member_spend_limit_updated"
A per-member Haijun Code spend limit amount was updated.
"workspace_spend_limit_alert_emails_updated"
Spend limit alert email recipients were updated for a workspace.
"workspace_spend_limit_created"
A workspace-level API spend limit was created.
"workspace_spend_limit_deleted"
A workspace-level API spend limit was deleted.
actor_ids: optional array of string
Filter activities by actor IDs (currently only user_... IDs are supported). Enumerate IDs via GET /v1/compliance/organizations/{org_uuid}/users.
after_id: optional string
Pagination cursor for retrieving the next page of results. To paginate, pass the last_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.
before_id: optional string
Pagination cursor for retrieving the previous page of results. To paginate, pass the first_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice.
created_at: optional object
gt: optional string
Filter activities created after this time (RFC 3339 format)
format: date-time
gte: optional string
Filter activities created at or after this time (RFC 3339 format)
format: date-time
lt: optional string
Filter activities created before this time (RFC 3339 format)
format: date-time
lte: optional string
Filter activities created at or before this time (RFC 3339 format)
format: date-time
exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more
Exclude activities of these types. Cannot be combined with activity_types[].
"abuse_decision_received"
An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.
"account_deleted"
User-initiated self-service account deletion.
"admin_api_key_created"
An admin API key was created.
"admin_api_key_deleted"
An admin API key was deleted.
"admin_api_key_updated"
An admin API key was updated (renamed or activated/deactivated).
"admin_connector_request_resolved"
Admin approved or dismissed pending member requests to enable an MCP connector.
"admin_request_created"
Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).
"admin_setup_checklist_step_delegated"
A step of the Haijun Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.
"admin_setup_checklist_step_delegation_cancelled"
The delegation of a Haijun Enterprise admin setup checklist step was cancelled.
"age_verified"
User age was verified.
"anonymous_mobile_login_attempted"
Anonymous mobile login was attempted.
"api_key_created"
Activity logged when a new API key is created.
"audit_log_export_accessed"
Audit log export file was accessed/downloaded via signed URL.
"audit_log_export_started"
Audit log export was initiated.
"billing_emails_updated"
The organization's billing email recipients were updated.
"ccr_agent_created"
A Haijun Code agent was created.
"ccr_agent_deleted"
A Haijun Code agent was deleted.
"ccr_agent_proxy_juglow_oidc_token_exchanged"
The Haijun Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.
"ccr_agent_proxy_juglow_oidc_token_minted"
The Haijun Code agent proxy minted a short-lived identity token for an juglow_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.
"ccr_agent_proxy_credential_created"
A Haijun Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Haijun Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.
"ccr_agent_proxy_credential_deleted"
A Haijun Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.
"ccr_agent_proxy_credential_rotated"
A Haijun Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.
"ccr_agent_proxy_credential_updated"
A Haijun Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.
"ccr_agent_proxy_destination_deleted"
An agent proxy destination was deleted.
"ccr_agent_proxy_network_events_listed"
A Haijun Code network activity export was accessed for the given hour.
"ccr_agent_proxy_profile_bound"
A Haijun Code agent proxy profile was bound to a scope, applying its policy to Haijun Code sessions in that scope.
"ccr_agent_proxy_profile_created"
A Haijun Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.
"ccr_agent_proxy_profile_deleted"
A Haijun Code agent proxy profile was deleted, removing its policy from everything it was bound to.
"ccr_agent_proxy_profile_unbound"
A Haijun Code agent proxy profile was unbound from a scope, removing its policy from Haijun Code sessions in that scope.
"ccr_agent_proxy_profile_updated"
A Haijun Code agent proxy profile's configuration was updated.
"ccr_agent_proxy_provisioning_credential_rejected"
An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.
"ccr_agent_proxy_provisioning_link_enabled"
An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.
"ccr_agent_proxy_provisioning_link_generated"
An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.
"ccr_agent_proxy_provisioning_link_revoked"
An organization owner revoked an unfilled agent proxy provisioning link.
"ccr_agent_proxy_provisioning_link_submitted"
A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.
"ccr_agent_proxy_rule_created"
An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.
"ccr_agent_proxy_rule_deleted"
An agent proxy rule was deleted.
"ccr_agent_proxy_rule_updated"
An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.
"ccr_agent_slack_access_scope_created"
A Haijun Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.
"ccr_agent_slack_access_scope_deleted"
A Haijun Code agent's access to an additional Slack channel was revoked.
"ccr_agent_slack_binding_created"
A Haijun Code agent was assigned to a Slack channel or workspace as its dedicated agent.
"ccr_agent_slack_binding_deleted"
A Haijun Code agent's assignment to a Slack channel or workspace was removed.
"ccr_agent_updated"
A Haijun Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.
"ccr_channel_manager_added"
An org owner/admin assigned an organization member to manage the Haijun-in-Slack configuration of one Slack channel.
"ccr_channel_manager_removed"
An org owner/admin removed an organization member's assignment to manage the Haijun-in-Slack configuration of one Slack channel.
"ccr_role_channel_assignment_deleted"
CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).
"ccr_role_channel_assignment_updated"
CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Haijun-in-Slack channel-manage surface.
"ccr_session_created"
A Haijun Code session was created. A session is one coding interaction with Haijun.
"ccr_session_deleted"
A Haijun Code session was deleted.
"ccr_session_updated"
A Haijun Code session's settings were updated.
"ccr_slack_channel_joined"
Haijun's Slack app joined a public Slack channel at an organization administrator's request.
"haijun_artifact_access_failed"
An attempt to access an artifact failed.
"haijun_artifact_commented"
Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.
"haijun_artifact_comments_viewed"
An artifact's comments were viewed.
"haijun_artifact_created"
An artifact was created.
"haijun_artifact_duplicated"
A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.
"haijun_artifact_external_sharing_permission_updated"
An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
"haijun_artifact_invite_accepted"
Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by invitee_email and invitee_user_id.
"haijun_artifact_invite_created"
A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
"haijun_artifact_invite_revoked"
A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
"haijun_artifact_invite_role_updated"
A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
"haijun_artifact_published"
A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as haijun_artifact_sharing_updated.
"haijun_artifact_sharing_updated"
An artifact's sharing settings were updated.
"haijun_artifact_viewed"
An artifact was viewed.
"haijun_chat_access_failed"
A user was denied access to a Haijun.ai chat conversation.
"haijun_chat_created"
User created a chat.
"haijun_chat_deleted"
A user deleted a Haijun.ai chat conversation.
"haijun_chat_deletion_failed"
A request to delete a Haijun.ai chat conversation failed.
"haijun_chat_settings_updated"
User updated the settings for a conversation.
"haijun_chat_snapshot_created"
User created/shared a chat snapshot.
"haijun_chat_snapshot_deleted"
User deleted/unshared a chat snapshot.
"haijun_chat_snapshot_viewed"
User viewed a chat snapshot (authenticated or public/unauthenticated).
"haijun_chat_sync_source_created"
A sync source was connected for syncing external content into Haijun chats.
"haijun_chat_sync_source_deleted"
A sync source was disconnected from Haijun chats.
"haijun_chat_sync_source_updated"
A Haijun chat sync source's configuration was updated.
"haijun_chat_updated"
User updated the chat metadata (e.g name, model).
"haijun_chat_viewed"
A user viewed a Haijun.ai chat conversation.
"haijun_code_credential_revoked"
A Haijun Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.
"haijun_code_review_config_updated"
Haijun Code Review configuration was enabled/disabled for an org.
"haijun_code_review_repository_added"
A repository was added to org-level Haijun Code Review configuration.
"haijun_code_review_repository_removed"
A repository was removed from org-level Haijun Code Review configuration.
"haijun_code_review_repository_updated"
A Haijun Code Review repository configuration was updated.
"haijun_code_runner_deleted"
A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.
"haijun_code_runner_pool_created"
A self-hosted runner pool for Haijun Code was created.
"haijun_code_runner_pool_deleted"
A self-hosted runner pool was deleted.
"haijun_code_runner_pool_secret_minted"
A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.
"haijun_code_runner_pool_session_queue_updated"
An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.
"haijun_code_runner_pool_updated"
A self-hosted runner pool's settings were updated.
"haijun_code_security_center_config_updated"
Haijun Code Security Center scanning was enabled/disabled for an org.
"haijun_code_security_scan_cancelled"
In-flight Haijun Code Security scans were cancelled for a project.
"haijun_code_security_scan_created"
A Haijun Code Security scan was started.
"haijun_code_security_scan_project_member_updated"
A person's access to a Haijun Code Security scan project was granted, changed, or revoked.
"haijun_code_security_scan_project_updated"
A Haijun Code Security scan project was archived, unarchived, created, or migrated to a new product experience.
"haijun_code_security_scan_project_visibility_updated"
A Haijun Code Security scan project was shared with the organization or made private.
"haijun_code_security_scan_run_updated"
A single Haijun Code Security scan run was archived, unarchived, or resumed after a billing pause.
"haijun_code_security_scan_schedule_deleted"
A recurring scan schedule was deleted for a Haijun Code Security project.
"haijun_code_security_scan_schedule_updated"
A recurring scan schedule was set or replaced for a Haijun Code Security project.
"haijun_code_security_vulnerability_deleted"
A Haijun Code Security vulnerability finding was permanently deleted.
"haijun_code_security_vulnerability_fix_session_created"
A Haijun Code remediation session was created for a Haijun Code Security vulnerability finding.
"haijun_code_security_vulnerability_updated"
A Haijun Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.
"haijun_code_security_webhook_created"
A Haijun Code Security outbound webhook was created.
"haijun_code_security_webhook_deleted"
A Haijun Code Security outbound webhook was deleted.
"haijun_code_security_webhook_secret_updated"
The HMAC signing secret for a Haijun Code Security webhook was rotated.
"haijun_code_security_webhook_updated"
A Haijun Code Security outbound webhook was updated.
"haijun_code_team_memory_acl_updated"
An RBAC group was added to or removed from the Haijun Code team-memory ACL.
"haijun_code_team_memory_updated"
Haijun Code team memory shared with the organization was updated.
"haijun_code_team_onboarding_guide_updated"
A Haijun Code team onboarding guide was created, updated, or deleted.
"haijun_code_user_marketplaces_updated"
A user's Haijun Code plugin marketplace selections were updated on Juglow servers.
"haijun_code_user_memory_updated"
A user's synced private Haijun Code memory was updated or deleted on Juglow servers.
"haijun_code_user_plugins_updated"
A user's Haijun Code plugin selections — which plugins are installed and enabled — were updated on Juglow servers.
"haijun_code_user_settings_updated"
A user's synced Haijun Code settings were updated or deleted on Juglow servers.
"haijun_command_created"
Command was created.
"haijun_command_deleted"
Command was deleted.
"haijun_command_replaced"
Command was replaced.
"haijun_enterprise_upgrade_credit_updated"
An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.
"haijun_file_access_failed"
A user was denied access to a file in Haijun.ai.
"haijun_file_deleted"
A file was deleted.
"haijun_file_exported"
A file was exported from Haijun to an external storage destination.
"haijun_file_uploaded"
A file was uploaded.
"haijun_file_viewed"
A user viewed a file in Haijun.ai.
"haijun_gdrive_integration_created"
A Google Drive integration was enabled for the organization.
"haijun_gdrive_integration_deleted"
A Google Drive integration was disabled for the organization.
"haijun_gdrive_integration_updated"
A Google Drive integration's configuration was updated.
"haijun_github_integration_created"
A GitHub integration was enabled for the organization.
"haijun_github_integration_deleted"
A GitHub integration was disabled for the organization.
"haijun_github_integration_updated"
A GitHub integration's configuration was updated.
"haijun_organization_settings_updated"
Organization settings were updated.
"haijun_plugin_archive_accessed"
A version archive of a member-owned plugin, containing that member's own files, was downloaded.
"haijun_plugin_created"
Plugin was created.
"haijun_plugin_deleted"
Plugin was deleted.
"haijun_plugin_disabled"
User disabled a plugin for their account.
"haijun_plugin_enabled"
User enabled a plugin for their account.
"haijun_plugin_replaced"
Plugin was replaced.
"haijun_plugin_security_scan_completed"
A security scan of a plugin completed and produced a verdict.
"haijun_plugin_updated"
Plugin was updated.
"haijun_project_archived"
A Haijun project was archived.
"haijun_project_created"
A Haijun project was created.
"haijun_project_deleted"
A Haijun project was deleted.
"haijun_project_document_access_failed"
An attempt to access a document in a Haijun project failed.
"haijun_project_document_bulk_deletion_audit_truncated"
A bulk request to delete documents from a Haijun project failed with more documents requested than were individually recorded in the audit log.
"haijun_project_document_deleted"
A document was deleted from a Haijun project.
"haijun_project_document_deletion_failed"
A request to delete a document from a Haijun project failed.
"haijun_project_document_updated"
The content of a document in a Haijun project was replaced in place.
"haijun_project_document_uploaded"
A document was uploaded to a Haijun project.
"haijun_project_document_viewed"
A document in a Haijun project was viewed.
"haijun_project_file_access_failed"
An attempt to access a file in a Haijun project failed.
"haijun_project_file_bulk_deletion_audit_truncated"
A bulk request to delete files from a Haijun project failed with more files requested than were individually recorded in the audit log.
"haijun_project_file_deleted"
A file was deleted from a Haijun project.
"haijun_project_file_deletion_failed"
A request to delete a file from a Haijun project failed.
"haijun_project_file_uploaded"
A file was uploaded to a Haijun project.
"haijun_project_reported"
A Haijun project was reported.
"haijun_project_sharing_updated"
A Haijun project's sharing settings were updated.
"haijun_project_sync_source_created"
A sync source was connected to a Haijun project's knowledge base.
"haijun_project_sync_source_deleted"
A sync source was disconnected from a Haijun project's knowledge base.
"haijun_project_sync_source_updated"
A Haijun project sync source's configuration was updated.
"haijun_project_viewed"
A Haijun project was viewed.
"haijun_published_artifact_deleted"
A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Juglow (for example, when it was removed for a policy violation).
"haijun_pubsec_identity_configured"
SAML IdP configuration updated for a public sector organization.
"haijun_skill_created"
Track was created.
"haijun_skill_deleted"
Track was deleted.
"haijun_skill_disabled"
User disabled a track for their account.
"haijun_skill_enabled"
User enabled a track for their account.
"haijun_skill_replaced"
Track was replaced.
"haijun_skill_security_scan_completed"
A security scan of a track completed and produced a verdict.
"haijun_user_role_updated"
A user's role within the organization was changed, or the user was added to or removed from the organization.
"haijun_user_seat_tier_updated"
An organization member's seat tier was changed. A null previous_seat_tier means the member previously had no seat assigned; a null current_seat_tier means the seat was removed.
"haijun_user_settings_updated"
User updated their personal settings.
"cli_plugin_exec_policy_updated"
Admin set or cleared the per-op permission ceiling for a plugin CLI.
"compliance_api_accessed"
Logging event auto-generated for each compliance API request.
"cowork_session_updated"
A Cowork session was updated.
"design_project_artifact_published"
A Haijun Design project's content was published as a haijun.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.
"design_project_created"
A Haijun Design project was created.
"design_project_deleted"
A Haijun Design project was deleted.
"design_project_member_added"
A member was granted access to a Haijun Design project.
"design_project_member_removed"
A member's access to a Haijun Design project was revoked.
"design_project_member_role_updated"
A Haijun Design project member's role was changed.
"design_project_published"
A Haijun Design template or design system was published, making it discoverable by everyone in its organization.
"design_project_sharing_updated"
A Haijun Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).
"design_project_unpublished"
A Haijun Design template or design system was unpublished, removing it from its organization's shared gallery.
"design_project_updated"
A Haijun Design project's metadata was updated.
"design_project_version_restored"
A Haijun Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.
"design_project_viewed"
A Haijun Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.
This activity type is retired: project content reads are no longer recorded. Events of this type may still appear in feeds for reads that occurred while it was active.
"desktop_extension_allowlisted"
A desktop extension was added to an org's allowlist.
"desktop_extension_blocklisted"
A desktop extension was added to the global blocklist.
"desktop_extension_deleted"
A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.
"desktop_extension_removed_from_allowlist"
A desktop extension was removed from an org's allowlist.
"desktop_extension_unblocked"
A desktop extension was removed from the global blocklist.
"desktop_extension_uploaded"
A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.
"desktop_extension_version_uploaded"
A new version of an existing org-owned desktop extension was uploaded.
"domain_claim_initiated"
Domain capture claim initiated over personal accounts on verified domains.
"end_user_invite_requested"
Non-admin member submitted an invite request for a new org member.
"extra_usage_billing_enabled"
Usage credit billing was enabled for an organization.
"extra_usage_credit_granted"
A promotional usage credit grant was claimed.
"extra_usage_spend_limit_created"
Usage credit spend limit was created.
"extra_usage_spend_limit_deleted"
Usage credit spend limit was deleted.
"extra_usage_spend_limit_increase_request_approved"
A usage credit spend limit increase request was approved.
"extra_usage_spend_limit_increase_request_denied"
A usage credit spend limit increase request was denied.
"extra_usage_spend_limit_updated"
Usage credit spend limit was updated.
"ghe_configuration_created"
Admin created a GHE configuration.
"ghe_configuration_deleted"
Admin deleted a GHE configuration.
"ghe_configuration_updated"
Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
"ghe_user_connected"
User connected to a GHE instance.
"ghe_user_disconnected"
User disconnected from a GHE instance.
"ghe_webhook_signature_invalid"
Webhook signature validation failed.
"github_app_installation_linked"
An installation of the Haijun GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Haijun Code features act on that GitHub account's repositories.
"github_app_installation_unlinked"
An installation of the Haijun GitHub App was unlinked from the organization, so the organization's Haijun Code features can no longer act on that GitHub account's repositories through it.
"github_token_import"
A user attempted to import a personal GitHub access token for use with Haijun Code. The result field indicates the outcome of the import (imported, rejected, or failed).
"gitlab_configuration_created"
An organization admin created a self-managed GitLab configuration for syncing plugin marketplaces.
"gitlab_configuration_deleted"
An organization admin deleted a self-managed GitLab configuration.
"gitlab_configuration_updated"
An organization admin updated a self-managed GitLab configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
"group_created"
A group was created (RBAC admin or SCIM provisioning).
"group_deleted"
A group was deleted (RBAC admin or SCIM provisioning).
"group_list_viewed"
Admin viewed the list of RBAC groups.
"group_member_added"
One or more members were added to a group.
"group_member_addition_failed"
A request to add members to a group failed. Some of the requested members may have been added before the failure.
"group_member_list_viewed"
Admin viewed the members of an RBAC group.
"group_member_removal_failed"
A request to remove members from a group failed. Some of the requested members may have been removed before the failure.
"group_member_removed"
One or more members were removed from a group.
"group_project_shares_revoked"
An RBAC group's project shares in one organization were revoked in bulk.
"group_skill_shares_revoked"
An RBAC group's track shares in one organization were revoked in bulk.
"group_updated"
A group was updated (RBAC admin or SCIM provisioning).
"group_viewed"
A group was viewed.
"group_visibility_updated"
An RBAC group's visibility policy was updated.
"inference_hooks_circuit_breaker_tripped"
The organization's Inference hooks circuit breaker tripped automatically: calls to the organization's Inference hooks endpoint crossed a failure threshold, and inspection was suspended to protect live traffic. While tripped, requests are handled according to the organization's failure handling setting — allowed through uninspected (fail open) or rejected (fail closed) — and no per-request Inference hooks activities are recorded. The tripped state persists until an administrator re-enables Inference hooks inspection (or explicitly resets the circuit breaker).
"inference_hooks_config_deleted"
Inference hooks configuration was removed for the organization.
"inference_hooks_config_updated"
Inference hooks configuration was created or updated for the organization.
"inference_hooks_request_denied"
Inference hooks inspection denied a request. The request was blocked and no model response was produced.
"inference_hooks_request_failed_open"
A request proceeded without Inference hooks inspection because a verdict could not be obtained and the organization's Inference hooks configuration is set to fail open.
"inference_hooks_signing_secret_generated"
A request signing secret was generated for the organization's Inference hooks configuration.
"integration_user_connected"
User connected to an integration.
"integration_user_disconnected"
User disconnected from an integration.
"invoice_collection_method_updated"
Invoice collection method was changed.
"lti_launch_initiated"
LTI launch was initiated.
"lti_launch_success"
LTI launch completed successfully.
"lti_platform_created"
Juglow staff created an LTI platform integration on behalf of an org.
"lti_platform_updated"
Juglow staff updated an LTI platform integration on behalf of an org.
"magic_link_login_failed"
A magic link sign-in attempt failed.
"magic_link_login_initiated"
A user requested a magic link sign-in email.
"magic_link_login_succeeded"
A user successfully signed in with a magic link email.
"managed_organization_setup_completed"
Managed (AWS Marketplace) organization setup was completed.
"marketplace_created"
Admin created an organization marketplace.
"marketplace_deleted"
Admin deleted an organization marketplace.
"marketplace_updated"
Admin updated an organization marketplace.
"marketplace_webhook_deleted"
Admin removed the GitHub push webhook for a marketplace.
"marketplace_webhook_provisioned"
Admin provisioned a GitHub push webhook for a marketplace.
"mcp_directory_server_published"
The organization published its approved MCP directory listing.
"mcp_server_created"
An MCP server was added to the organization.
"mcp_server_deleted"
An MCP server was removed from the organization.
"mcp_server_managed_auth_token_exchanged"
A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
"mcp_server_managed_auth_updated"
An MCP server's enterprise managed authorization settings were set, changed, or cleared, including when they were supplied while the server was being added or edited. Fields without a "previous_" prefix describe the settings after the change and are null when the server has no managed authorization settings afterwards; "previous_" fields describe the settings before the change and are null when the server had none before (always the case for a newly added server).
"mcp_server_updated"
An MCP server's configuration was updated.
"mcp_tool_policy_updated"
The permission restriction for an MCP tool was set or cleared.
"org_analytics_api_capability_updated"
Organization analytics_api capability was enabled or disabled.
"org_bulk_delete_initiated"
Organization bulk deletion was initiated.
"org_capability_grant_added"
A capability grant was added to a workspace or role.
"org_capability_grant_removed"
A capability grant was removed from a workspace or role.
"org_haijun_code_data_sharing_disabled"
Organization Haijun Code data sharing was disabled.
"org_haijun_code_data_sharing_enabled"
Organization Haijun Code data sharing was enabled.
"org_haijun_code_desktop_disabled"
Organization Haijun Code Desktop was disabled.
"org_haijun_code_desktop_enabled"
Organization Haijun Code Desktop was enabled.
"org_haijun_code_zero_data_retention_disabled"
A primary owner disabled zero data retention for Haijun Code, so Haijun Code content is retained according to the organization's data retention settings.
"org_compliance_api_settings_updated"
Organization compliance API settings were updated.
"org_connector_domain_guard_updated"
Enterprise admin changed whether connectors are restricted to verified domains.
"org_cowork_act_without_asking_mode_disabled"
The "Act without asking" mode in Cowork was disabled for the organization, so members can no longer let Haijun act without asking for approval.
"org_cowork_act_without_asking_mode_enabled"
The "Act without asking" mode in Cowork was enabled for the organization, allowing members to let Haijun act without asking for approval.
"org_cowork_agent_disabled"
Organization Cowork Agent was disabled.
"org_cowork_agent_enabled"
Organization Cowork Agent was enabled.
"org_cowork_auto_mode_disabled"
The "Auto" permission mode in Cowork was disabled for the organization, so members can no longer let Haijun approve its own actions after a safety check.
"org_cowork_auto_mode_enabled"
The "Auto" permission mode in Cowork was enabled for the organization, allowing members to let Haijun approve its own actions after a safety check.
"org_cowork_browser_pane_disabled"
The in-app browser in Cowork was disabled for the organization, so Haijun can no longer open or use websites in a browser pane during members' Cowork sessions.
"org_cowork_browser_pane_enabled"
The in-app browser in Cowork was enabled for the organization, letting Haijun open and use websites in a browser pane during members' Cowork sessions.
"org_cowork_disabled"
Organization cowork was disabled.
"org_cowork_enabled"
Organization cowork was enabled.
"org_cowork_mcp_always_allow_disabled"
The "Always allow" option for connector tools in Cowork was disabled for the organization, so each use of a connector tool that can make changes requires approval. Read-only connector tools are not affected by this setting.
"org_cowork_mcp_always_allow_enabled"
The "Always allow" option for connector tools in Cowork was enabled for the organization, letting members approve a connector tool that can make changes once and allow its later uses automatically. Read-only connector tools are not affected by this setting.
"org_cowork_otlp_settings_updated"
The organization's Cowork OpenTelemetry monitoring export settings were updated.
"org_cowork_remote_disabled"
Running Cowork in the cloud was disabled for the organization, so members can no longer run Cowork sessions in Juglow-hosted remote environments.
"org_cowork_remote_enabled"
Running Cowork in the cloud was enabled for the organization, allowing members to run Cowork sessions in Juglow-hosted remote environments.
"org_creation_blocked"
Organization creation was blocked.
"org_data_export_accessed"
Organization data export file was accessed/downloaded via signed URL.
"org_data_export_completed"
Organization data export was completed.
"org_data_export_started"
Organization data export was started.
"org_data_residency_updated"
The organization's inference data residency settings were updated.
"org_deleted_via_bulk"
Organization was deleted via bulk operation.
"org_deletion_requested"
Organization deletion was requested.
"org_directory_resync_completed"
Organization directory resync completed successfully.
"org_directory_resync_failed"
Organization directory resync failed.
"org_directory_resync_started"
Organization directory resync was started asynchronously.
"org_directory_sync_activated"
Organization directory sync was activated.
"org_directory_sync_add_initiated"
Organization directory sync setup was initiated.
"org_directory_sync_deleted"
Organization directory sync was deleted.
"org_discoverability_disabled"
Admin disabled organization discoverability.
"org_discoverability_enabled"
Admin enabled organization discoverability.
"org_discoverability_settings_updated"
Admin updated organization discoverability settings.
"org_domain_add_initiated"
Organization domain verification was initiated.
"org_domain_removed"
Organization domain was removed.
"org_domain_verified"
Organization domain was verified.
"org_external_key_created"
A CMEK external key config was created.
"org_external_key_deleted"
A CMEK external key config was deleted.
"org_external_key_updated"
A CMEK external key config was updated.
"org_external_key_validated"
A CMEK external key config was validated against the customer's KMS.
"org_hipaa_self_serve_enabled"
A primary owner click-accepted the BAA and enabled HIPAA protections for the organization via the self-serve flow.
"org_invite_link_disabled"
Organization invite link was disabled.
"org_invite_link_generated"
Organization invite link was generated.
"org_invite_link_regenerated"
Organization invite link was regenerated (previous link invalidated).
"org_invite_viewed"
An organization invite was viewed.
"org_invites_listed"
Organization invites were listed.
"org_ip_restriction_created"
Organization IP restriction was created.
"org_ip_restriction_deleted"
Organization IP restriction was deleted.
"org_ip_restriction_updated"
Organization IP restriction was updated.
"org_join_proposal_decided"
Approve or reject decision on a parent-org join proposal.
"org_join_request_approved"
Admin approved a join request.
"org_join_request_created"
User requested to join an organization.
"org_join_request_dismissed"
Admin dismissed a join request.
"org_join_request_instant_approved"
Join request was instantly approved.
"org_join_requests_bulk_dismissed"
Admin bulk-dismissed join requests.
"org_magic_link_second_factor_toggled"
Organization magic link second factor was toggled.
"org_member_invites_disabled"
Admin disabled member invites for the organization.
"org_member_invites_enabled"
Admin enabled member invites for the organization.
"org_members_exported"
Organization members list was exported as CSV.
"org_model_default_updated"
An organization or role default model setting was changed by an administrator.
"org_parent_join_proposal_created"
Organization parent join proposal was created.
"org_parent_search_performed"
Organization parent search was performed.
"org_sso_add_initiated"
Organization SSO setup was initiated.
"org_sso_connection_activated"
Organization SSO connection was activated.
"org_sso_connection_deactivated"
Organization SSO connection was deactivated.
"org_sso_connection_deleted"
Organization SSO connection was deleted.
"org_sso_group_role_mappings_updated"
Organization SSO group role mappings were updated.
"org_sso_provisioning_mode_changed"
Organization SSO provisioning mode was changed.
"org_sso_scim_welcome_email_toggled"
Organization SCIM-provisioned welcome email was toggled.
"org_sso_seat_tier_assignment_toggled"
Organization SSO seat tier assignment was toggled.
"org_sso_seat_tier_mappings_updated"
Organization SSO seat tier mappings were updated.
"org_sso_toggled"
Organization SSO was toggled on or off.
"org_sync_deleting_synchronized_files_started"
Organization started deleting synchronized files.
"org_sync_synchronized_files_deleted"
Organization synchronized files were deleted.
"org_taint_added"
A taint was added to an organization.
"org_taint_removed"
A taint was removed from an organization.
"org_user_deleted"
User was removed from organization.
"org_user_invite_accepted"
Organization user invite was accepted.
"org_user_invite_deleted"
Organization user invite was deleted.
"org_user_invite_re_sent"
Organization user invite was re-sent.
"org_user_invite_rejected"
Organization user invite was rejected.
"org_user_invite_sent"
Organization user invite was sent.
"org_user_left"
User removed themselves from organization.
"org_user_shares_retained"
A member left or was removed from the organization while projects, tracks, plugins, or chats they had shared were still shared, and those shares were kept.
"org_user_trusted_devices_revoked"
An organization admin revoked a member's trusted devices and signed the member out of all active sessions.
"org_user_viewed"
An organization user was viewed.
"org_users_listed"
Organization users were listed.
"org_work_across_apps_disabled"
The organization's "Let Haijun work across apps" setting was turned off.
"org_work_across_apps_enabled"
The organization's "Let Haijun work across apps" setting was turned on.
"organization_address_updated"
The organization's billing or shipping address was updated.
"organization_icon_deleted"
Organization's custom icon deleted.
"organization_icon_updated"
Organization's custom icon uploaded or replaced.
"owned_projects_access_restored"
Access to owned projects was restored.
"payment_method_updated"
The organization's default payment method was updated.
"pending_share_created"
A pending share of a project or track was created for an email address that is not yet an organization member.
"pending_share_revoked"
A pending share of a project or track was revoked before the invitee joined the organization.
"phone_code_sent"
User requested a phone verification code.
"phone_code_verified"
User successfully verified their phone code.
"platform_agent_archived"
An agent was archived on the API platform.
"platform_agent_created"
An agent was created on the API platform.
"platform_agent_deleted"
An agent was deleted from the API platform.
"platform_agent_deployment_archived"
An agent deployment was archived on the API platform.
"platform_agent_deployment_created"
An agent deployment was created on the API platform.
"platform_agent_deployment_deleted"
An agent deployment was deleted from the API platform.
"platform_agent_deployment_paused"
An agent deployment was paused on the API platform.
"platform_agent_deployment_run_triggered"
An agent deployment was run on demand on the API platform.
"platform_agent_deployment_unpaused"
An agent deployment was resumed on the API platform.
"platform_agent_deployment_updated"
An agent deployment was updated on the API platform.
"platform_agent_session_archived"
An agent session was archived on the API platform.
"platform_agent_session_created"
An agent session was created on the API platform.
"platform_agent_session_deleted"
An agent session was deleted from the API platform.
"platform_agent_session_resource_added"
A resource was attached to an agent session.
"platform_agent_session_resource_deleted"
A resource attached to an agent session was removed.
"platform_agent_session_resource_updated"
A resource attached to an agent session was updated.
"platform_agent_session_thread_archived"
A thread within an agent session was archived.
"platform_agent_session_updated"
An agent session was updated on the API platform.
"platform_agent_updated"
An agent was updated on the API platform.
"platform_api_key_created"
An API key was created.
"platform_api_key_updated"
An API key was updated.
"platform_app_attest_authentication"
An attested mobile device attempted to exchange an Apple App Attest assertion for Juglow API credentials.
"platform_billing_upgraded_to_prepaid"
The organization's API billing was upgraded to the prepaid plan.
"platform_clearance_workspace_program_request_cleared"
A workspace's clearance program assignment was removed.
"platform_clearance_workspace_program_request_set"
A workspace's clearance program assignment was created or updated.
"platform_cost_report_viewed"
The cost report was viewed.
"platform_dream_archived"
A Dream (asynchronous memory-consolidation job) was archived.
"platform_dream_cancelled"
A Dream (asynchronous memory-consolidation job) was cancelled before it completed.
"platform_dream_created"
A Dream (asynchronous memory-consolidation job) was created.
"platform_federated_authentication"
A federated workload identity attempted to exchange an OIDC token for Juglow API credentials.
"platform_federation_issuer_archived"
An OIDC federation issuer was archived.
"platform_federation_issuer_created"
An OIDC federation issuer was created, registering an external identity provider that federation rules can trust for workload authentication.
"platform_federation_issuer_updated"
An OIDC federation issuer was updated.
"platform_federation_rule_archived"
An OIDC federation rule was archived.
"platform_federation_rule_created"
An OIDC federation rule was created, allowing tokens from a federation issuer to authenticate as a service account or user. Rules may additionally match on token claims or a condition expression, which are not included in this event.
"platform_federation_rule_updated"
An OIDC federation rule was updated.
"platform_federation_rule_workspace_added"
A federation rule was enabled for a workspace.
"platform_federation_rule_workspace_removed"
A federation rule was disabled for a workspace.
"platform_file_content_downloaded"
Activity logged when file content is downloaded via GET /v1/files/{file_id}/content.
"platform_file_deleted"
Activity logged when a file is deleted via DELETE /v1/files/{file_id}.
"platform_file_uploaded"
Activity logged when a file is uploaded via POST /v1/files.
"platform_memory_created"
An agent memory document was created.
"platform_memory_deleted"
An agent memory document was deleted.
"platform_memory_store_archived"
An agent memory store was archived. Archived stores reject new memory writes and cannot be attached to new sessions; deletion and redaction remain permitted for privacy scrubbing.
"platform_memory_store_created"
An agent memory store was created.
"platform_memory_store_deleted"
An agent memory store was deleted. Memory content removal may complete asynchronously for very large stores.
"platform_memory_store_updated"
An agent memory store's name, description, or metadata was updated.
"platform_memory_updated"
An agent memory document's content or path was updated.
"platform_memory_version_redacted"
A historical version of an agent memory document was redacted. Redaction scrubs the stored content of a specific version while preserving the version's existence in the history.
"platform_oauth_app_created"
An OAuth app was created.
"platform_oauth_app_revoked"
An OAuth app was revoked.
"platform_oauth_app_updated"
An OAuth app was updated.
"platform_plugin_directory_submission_created"
A plugin directory submission was created on the API platform. A plugin directory submission is a request to list a plugin in the public plugin directory.
"platform_plugin_directory_submission_deleted"
A plugin directory submission was deleted on the API platform.
"platform_plugin_directory_submission_updated"
A plugin directory submission was updated on the API platform.
"platform_service_account_archived"
A service account was archived.
"platform_service_account_created"
A service account was created.
"platform_service_account_updated"
A service account was updated.
"platform_service_account_workspace_member_added"
A service account was added as a member of a workspace.
"platform_service_account_workspace_member_removed"
A service account was removed from a workspace.
"platform_service_account_workspace_member_updated"
A service account's workspace membership role was updated.
"platform_signing_key_created"
Activity logged when a new request-signing key is registered for the org.
"platform_signing_key_deleted"
Activity logged when a signing key is permanently deleted.
"platform_signing_key_rotated"
Activity logged when an in-memory signing key is rotated.
"platform_skill_version_content_downloaded"
The content of a track version was downloaded through the Tracks API.
"platform_skill_version_created"
Activity logged when a track version is created via POST /v1/tracks/{skill_id}/versions.
"platform_skill_version_deleted"
Activity logged when a track version is deleted via DELETE /v1/tracks/{skill_id}/versions/{version}.
"platform_spend_limit_alert_emails_updated"
Spend limit alert email addresses and role targets were updated for an org.
"platform_spend_limit_created"
An org-level fixed-dollar spend limit was created.
"platform_spend_limit_deleted"
An org-level spend limit was removed.
"platform_spend_limit_updated"
An org-level spend limit snooze/ignore state was changed.
"platform_usage_report_haijun_code_viewed"
The Haijun Code usage report was viewed.
"platform_usage_report_messages_viewed"
The messages usage report was viewed.
"platform_workspace_archived"
A workspace was archived.
"platform_workspace_created"
A workspace was created.
"platform_workspace_inference_data_retention_disabled"
The zero data retention override was disabled for a workspace.
"platform_workspace_inference_data_retention_enabled"
The zero data retention override was enabled for a workspace.
"platform_workspace_member_added"
A member was added to a workspace.
"platform_workspace_member_removed"
A member was removed from a workspace.
"platform_workspace_member_updated"
A workspace member was updated.
"platform_workspace_member_viewed"
A workspace member was viewed.
"platform_workspace_members_listed"
Workspace members were listed.
"platform_workspace_rate_limit_deleted"
A workspace rate limit was deleted.
"platform_workspace_rate_limit_updated"
A workspace rate limit was created or updated.
"platform_workspace_updated"
A workspace was updated.
"plugin_installation_preference_updated"
An org admin changed the installation preference for a plugin.
"prepaid_auto_recharge_disabled"
Auto-recharge was disabled for API prepaid org.
"prepaid_auto_recharge_updated"
Auto-recharge settings were updated for API prepaid org.
"prepaid_extra_usage_auto_reload_disabled"
Prepaid usage credit auto-reload was disabled.
"prepaid_extra_usage_auto_reload_enabled"
Prepaid usage credit auto-reload was enabled.
"prepaid_extra_usage_auto_reload_settings_updated"
Prepaid usage credit auto-reload settings were updated.
"primary_owner_transferred"
Primary owner role was transferred to another org member.
"rbac_role_assigned"
Admin assigned an RBAC custom role to a principal.
"rbac_role_created"
Admin created an RBAC custom role.
"rbac_role_deleted"
Admin deleted an RBAC custom role.
"rbac_role_grant_updated"
Admin requested a capability grant for an RBAC custom role, or removed it.
Records the admin's change to the role. Whether the grant is currently in effect on the role is reported separately.
"rbac_role_permission_added"
Admin added a permission to an RBAC custom role.
Emitted once per requested permission, including permissions the role already had, so a retried request still produces a complete audit record.
"rbac_role_permission_removed"
Admin removed a permission from an RBAC custom role.
Emitted once per requested permission, including permissions the role already lacked, so a retried request still produces a complete audit record.
"rbac_role_unassigned"
Admin unassigned an RBAC custom role from a principal.
"rbac_role_updated"
Admin updated an RBAC custom role.
"role_assignment_granted"
Role assignment was granted.
"role_assignment_revoked"
Role assignment was revoked.
"scim_user_created"
A SCIM user was provisioned.
"scim_user_deleted"
A SCIM user was deleted.
"scim_user_updated"
A SCIM user was updated.
"scoped_api_key_deleted"
A scoped API key was deleted.
"scoped_api_key_updated"
A scoped API key was renamed or its activation state changed.
"seat_tier_changes_cancelled"
Scheduled seat tier downgrades were cancelled.
"seat_tiers_purchased"
Seat tiers were purchased or upgraded on a subscription.
"service_created"
Activity logged when an org service is explicitly created.
"service_deleted"
Activity logged when an org service is deleted.
"service_key_created"
Activity logged when a new org service key is created.
"service_key_revoked"
Activity logged when an org service key is revoked.
"session_revoked"
User revoked a specific session.
"session_share_accessed"
Session share was accessed.
"session_share_created"
Session share was created.
"session_share_revoked"
Session share was revoked.
"slack_workspace_claim_revoked"
A Slack workspace or Enterprise Grid organization was disconnected from the organization for Haijun in Slack.
"slack_workspace_claimed"
A Slack workspace or Enterprise Grid organization was connected to the organization for Haijun in Slack.
"social_login_succeeded"
A user successfully signed in with a social identity provider (Google, Apple, or Microsoft).
"sso_login_failed"
An SSO sign-in attempt failed.
"sso_login_initiated"
A user started an SSO sign-in flow.
"sso_login_succeeded"
A user successfully signed in with SSO.
"sso_second_factor_magic_link"
SSO second factor magic link was used.
"step_up_authentication_failed"
An additional identity check failed.
"step_up_authentication_succeeded"
The user completed an additional identity check to confirm a sensitive action.
"step_up_credential_enrolled"
A user enrolled a passkey for confirming sensitive actions on their account.
"subscription_cancellation_scheduled"
Subscription cancellation was scheduled at end of billing period.
"subscription_quantity_updated"
Contracted subscription seat quantity was updated.
"subscription_renewed"
A cancelled subscription was renewed.
"subscription_resumed"
A scheduled subscription cancellation was reversed.
"subscription_started"
A new subscription was created (Team or Enterprise).
"subscription_upgraded"
Subscription plan was upgraded (e.g. Team to Enterprise).
"trusted_device_credential_rotated"
The identity-verification credential of a trusted device was rotated to a new key.
"trusted_device_enrolled"
A device was enrolled as a trusted device for the user's account. Trusted devices can be used to confirm the user's identity for sensitive actions.
"trusted_device_revoked"
A trusted device was removed from the user's account.
"tunnel_archived"
An MCP tunnel was archived.
"tunnel_certificate_added"
An inner-TLS CA certificate was added to a tunnel.
"tunnel_certificate_revoked"
An inner-TLS CA certificate was revoked from a tunnel.
"tunnel_created"
An MCP tunnel was created.
"tunnel_token_minted"
An OAuth bearer token for the tunnel management API was minted.
"tunnel_token_revealed"
The Cloudflare connector secret for a tunnel was revealed to the caller.
"tunnel_token_revoked"
An OAuth bearer token for the tunnel management API was revoked.
"tunnel_token_rotated"
The Cloudflare connector secret for a tunnel was rotated.
tunnel_token_id is the id of the newly-issued token. The previous token is invalidated by the rotation and its id is not recorded here.
"user_consent_recorded"
User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).
"user_consent_revoked"
User revoked a previously granted consent for a specific entity.
"user_logged_out"
A user signed out of one or all sessions.
"verification_evidence_submitted"
Verification evidence was submitted for an organization's verification.
"verification_program_application_created"
An organization applied to a verification program.
"workspace_member_spend_limit_created"
A per-member or workspace-default Haijun Code spend limit was created.
"workspace_member_spend_limit_deleted"
A per-member or workspace-default Haijun Code spend limit was deleted.
"workspace_member_spend_limit_updated"
A per-member Haijun Code spend limit amount was updated.
"workspace_spend_limit_alert_emails_updated"
Spend limit alert email recipients were updated for a workspace.
"workspace_spend_limit_created"
A workspace-level API spend limit was created.
"workspace_spend_limit_deleted"
A workspace-level API spend limit was deleted.
limit: optional number
Maximum results (default: 100, max: 5000)
default: 100, minimum: 1, maximum: 5000
order: optional "asc" or "desc"
Sort direction by created_at. desc (default) returns newest-first; asc returns oldest-first for incremental sync. Activities become queryable after a short asynchronous ingestion delay. When using asc with after_id for incremental sync, late-arriving rows with timestamps behind the cursor will be skipped; consumers that need at-least-once delivery should periodically re-poll an overlap window via created_at.gte and deduplicate by id. after_id and before_id are relative to this order.
default: desc
"asc"
"desc"
organization_ids: optional array of string
Filter activities by organization IDs (accepts org_... or organization UUID). Enumerate IDs via GET /v1/compliance/organizations.
user_ids: optional array of string
Alias for actor_ids[], for consistency with other compliance routes. If both are provided, the lists are merged.
Headers
"x-api-key": optional string
Returns
data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 511 more
List of activity records. Each element's type field identifies which activity it is and which additional fields are present.
AbuseDecisionReceived object
An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.
type: optional "abuse_decision_received"
default: abuse_decision_received
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
decision: "blocked" or "unspecified"
The decision applied to the session.
"blocked"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
abuse_session_id: optional string or null
The anti-abuse service's opaque session identifier for correlation.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AccountDeleted object
User-initiated self-service account deletion.
type: optional "account_deleted"
default: account_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AdminAPIKeyCreated object
An admin API key was created.
type: optional "admin_api_key_created"
default: admin_api_key_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
admin_api_key_id: string
Tagged ID of the created admin API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scopes: optional array of string
Scopes granted to the key (empty for legacy non-scoped admin keys)
AdminAPIKeyDeleted object
An admin API key was deleted.
type: optional "admin_api_key_deleted"
default: admin_api_key_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
admin_api_key_id: string
Tagged ID of the deleted admin API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AdminAPIKeyUpdated object
An admin API key was updated (renamed or activated/deactivated).
type: optional "admin_api_key_updated"
default: admin_api_key_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
admin_api_key_id: string
Tagged ID of the updated admin API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "name" or "status" or "unspecified"
The admin API key field that changed
"name"
"status"
"unspecified"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
AdminConnectorRequestResolved object
Admin approved or dismissed pending member requests to enable an MCP connector.
type: optional "admin_connector_request_resolved"
default: admin_connector_request_resolved
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
decision: "approved" or "dismissed" or "unspecified"
"approved"
"dismissed"
"unspecified"
mcp_server_id: string
resolved_count: number
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AdminRequestCreated object
Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).
type: optional "admin_request_created"
default: admin_request_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
request_type: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AdminSetupChecklistStepDelegated object
A step of the Haijun Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.
type: optional "admin_setup_checklist_step_delegated"
default: admin_setup_checklist_step_delegated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
step: string
The checklist step that was delegated, for example enable_sso or verify_domain.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
delegate_email: optional string or null
Email address the step was delegated to; present only when the delegate is not yet an organization member.
delegate_user_id: optional string or null
Tagged ID of the organization member the step was delegated to; absent when the step was delegated to an email address that has not joined the organization.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AdminSetupChecklistStepDelegationCancelled object
The delegation of a Haijun Enterprise admin setup checklist step was cancelled.
type: optional "admin_setup_checklist_step_delegation_cancelled"
default: admin_setup_checklist_step_delegation_cancelled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
step: string
The checklist step whose delegation was cancelled.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AgeVerified object
User age was verified.
type: optional "age_verified"
default: age_verified
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AnonymousMobileLoginAttempted object
Anonymous mobile login was attempted.
type: optional "anonymous_mobile_login_attempted"
default: anonymous_mobile_login_attempted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
APIKeyCreated object
Activity logged when a new API key is created.
type: optional "api_key_created"
default: api_key_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
api_key_id: string
The tagged ID of the created API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
restricted_to_organization: optional boolean or null
Whether the key was restricted to the creating organization, rather than granted access across the whole parent organization
scopes: optional array of string
The scopes for this API key
HaijunArtifactAccessFailed object
An attempt to access an artifact failed.
type: optional "haijun_artifact_access_failed"
default: haijun_artifact_access_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_artifact_id: optional string or null
The artifact's identifier, when known.
haijun_artifact_version_id: optional string or null
The version of the artifact the user attempted to access, when known.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
reason: optional string or null
The reason access was denied, when recorded.
HaijunArtifactCommented object
Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.
type: optional "haijun_artifact_commented"
default: haijun_artifact_commented
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
The artifact's identifier.
comment_action: "activate_thread" or "create_thread" or "deactivate_thread" or 10 more
The action recorded: for example a new comment thread, a reply to an existing thread, a thread resolved, reopened, or deleted, a thread's Haijun activation granted or revoked, a comment's text rewritten by its author, an existing comment sent to Haijun or withdrawn from Haijun, or a thread resolved by a Haijun session.
"activate_thread"
"create_thread"
"deactivate_thread"
"delete_thread"
"edit_comment"
"move_thread"
"reopen"
"reply"
"resolve"
"send_to_haijun"
"session_resolve"
"unsend_to_haijun"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
actor_outside_organization: optional boolean or null
True when the person who acted belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted commenter or editor access. Absent on older events; treat absence as false.
haijun_artifact_comment_id: optional string or null
The comment's identifier. Present when the activity relates to a specific comment, for example a new comment, an author's edit of one, or an existing comment sent to Haijun or withdrawn from Haijun; absent for thread-level actions performed without a comment, such as resolve, reopen, deletion, an activation change, or a resolve by a Haijun session.
haijun_artifact_comment_thread_id: optional string or null
The comment thread's identifier.
haijun_artifact_version_id: optional string or null
The artifact version the comment activity applied to, when known.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactCommentsViewed object
An artifact's comments were viewed.
type: optional "haijun_artifact_comments_viewed"
default: haijun_artifact_comments_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
The artifact's identifier.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_artifact_version_id: optional string or null
The version of the artifact whose comments were served, when known.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactCreated object
An artifact was created.
type: optional "haijun_artifact_created"
default: haijun_artifact_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
Tagged ID of the artifact that was created, e.g. "haijun_artifact_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunPublishedArtifactDeleted object
A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Juglow (for example, when it was removed for a policy violation).
type: optional "haijun_published_artifact_deleted"
default: haijun_published_artifact_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_published_artifact_id: string
The published artifact's identifier.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactPublished object
A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as haijun_artifact_sharing_updated.
type: optional "haijun_artifact_published"
default: haijun_artifact_published
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
artifact_type: string
Artifact type (code, html, react, etc.)
haijun_published_artifact_id: string
The published artifact's identifier.
title: string
Title of the published artifact
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
actor_outside_organization: optional boolean or null
True when the person who published belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted editor access. Absent on older events; treat absence as false.
haijun_artifact_version_id: optional string or null
The version identifier recorded as live by this publish.
created_at: optional string
When this activity occurred.
format: date-time
description: optional string or null
No longer populated: the gallery-card description supplied at publish time is intentionally omitted from this feed.
is_redeploy: optional boolean or null
True when the publish updated an existing artifact; false when the publish created the artifact.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactSharingUpdated object
An artifact's sharing settings were updated.
type: optional "haijun_artifact_sharing_updated"
default: haijun_artifact_sharing_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
audience: array of Organization or Users or AnyoneWithLink
The artifact's sharing audience after the change. If empty, the artifact is visible only to its owner.
Organization object
Sharing audience: visible to the owning organization.
type: optional "organization"
default: organization
Users object
Sharing audience: visible to an explicit allowlist of users.
type: optional "users"
default: users
AnyoneWithLink object
Sharing audience: anyone with the link, including anonymous viewers (an artifact shared to the open internet).
type: optional "anyone_with_link"
default: anyone_with_link
haijun_artifact_id: string
The artifact's identifier.
haijun_artifact_version_id: string
The artifact version's identifier.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
new_mode: optional string or null
The read-axis sharing mode after the change: owner, users, org, or public (anyone on the internet).
new_user_count: optional number or null
The number of accounts on the explicit read allowlist after the change. Only meaningful when new_mode is users.
new_write_mode: optional string or null
The write-axis sharing mode after the change: owner, users, or org.
new_write_user_count: optional number or null
The number of accounts on the explicit write allowlist after the change. Only meaningful when new_write_mode is users.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_mode: optional string or null
The read-axis sharing mode before the change: owner, users, org, or public (anyone on the internet).
previous_user_count: optional number or null
The number of accounts on the explicit read allowlist before the change. Only meaningful when previous_mode is users.
previous_write_mode: optional string or null
The write-axis sharing mode before the change: owner, users, or org.
previous_write_user_count: optional number or null
The number of accounts on the explicit write allowlist before the change. Only meaningful when previous_write_mode is users.
HaijunArtifactViewed object
An artifact was viewed.
type: optional "haijun_artifact_viewed"
default: haijun_artifact_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
The artifact's identifier.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_artifact_version_id: optional string or null
The version of the artifact the user was served, when known.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AuditLogExportAccessed object
Audit log export file was accessed/downloaded via signed URL.
type: optional "audit_log_export_accessed"
default: audit_log_export_accessed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
AuditLogExportStarted object
Audit log export was initiated.
type: optional "audit_log_export_started"
default: audit_log_export_started
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
from_date: optional string or null
Start date of the export range
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
to_date: optional string or null
End date of the export range
BillingEmailsUpdated object
The organization's billing email recipients were updated.
type: optional "billing_emails_updated"
default: billing_emails_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
cc_email_count: optional number or null
Number of 'cc' email recipients.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
primary_email_set: optional boolean or null
Whether a primary billing email is configured.
to_email_count: optional number or null
Number of 'to' email recipients.
CcrAgentCreated object
A Haijun Code agent was created.
type: optional "ccr_agent_created"
default: ccr_agent_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was created, e.g. "cagt_01HX...".
default_source_urls_truncated: boolean
Whether default_source_urls was capped and omits some of the granted repositories.
display_name: string
The agent's display name at creation time.
omitted_source_url_count: number
Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.
slug: string
The agent's URL-safe identifier, unique within the organization.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
default_source_urls: optional array of string
The repository URLs the agent works on by default, reduced to scheme, host, and path — credentials and query parameters are never included. Empty with a zero omitted_source_url_count means the agent was created without any default repositories; empty with a non-zero count means repositories were granted but could not be safely rendered. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.
guest_policy: optional string or null
Whether the agent responds in Slack channels that include guest users, and in Slack Connect channels shared with other organizations: "allow", "restrict", or "channel" (the agent responds, using only that channel's own content and configuration). In Slack Connect channels "allow" gives at most "channel" access. Omitted when the agent inherits the default policy.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
slack_alias: optional string or null
The Slack trigger word that routes mentions to this agent. An empty value means the agent responds to bare "@Haijun" mentions. Omitted when the agent is not addressable from Slack.
CcrAgentDeleted object
A Haijun Code agent was deleted.
type: optional "ccr_agent_deleted"
default: ccr_agent_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was deleted, e.g. "cagt_01HX...".
cascaded_agent_ids_truncated: boolean
True when more agents were deleted in this cascade than are individually recorded. On a cascade parent event (cascaded_from_agent_id unset), cascaded_agent_ids is capped at 100. On a cascade child event (cascaded_from_agent_id set, emitted when the parent deletion failed after committing child deletions), one event is emitted per deleted child up to 100, and this field indicates additional children were deleted in the same cascade.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
cascaded_agent_ids: optional array of string
Agents assigned to individual Slack channels that were also deleted because agent_id was the agent assigned to their entire Slack workspace. Empty when no such agents were deleted, and always empty on a cascade child event (cascaded_from_agent_id set) — the child's siblings are recorded as their own events, not listed here. Capped at 100 entries; cascaded_agent_ids_truncated is set when the actual count exceeded the cap.
cascaded_from_agent_id: optional string or null
When set, the Slack workspace's dedicated agent whose deletion attempt caused this agent to be deleted. The parent's own deletion may have failed after the cascade committed — check for a separate event with agent_id = cascaded_from_agent_id to confirm. Unset on a direct deletion.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyJuglowOidcTokenExchanged object
The Haijun Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.
type: optional "ccr_agent_proxy_juglow_oidc_token_exchanged"
default: ccr_agent_proxy_juglow_oidc_token_exchanged
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The Haijun Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.
credential_id: string
The credential row the exchange ran for, e.g. "apc_01HX...".
profile_id: string
The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
role_arn: string
The IAM role the token was exchanged for ("aws" target), e.g. "arn:aws:iam::123456789012:role/example-role". Empty for other targets.
role_session_name: string
The role session name the temporary credentials were issued under ("aws" target), matching the session name recorded in the organization's own AWS CloudTrail log. Empty for other targets.
service_account: string
The Google Cloud service account the federated token was exchanged into ("gcp" target), e.g. "example@example-project.iam.gserviceaccount.com". Empty when the federated token was used directly, and for other targets.
session_id: string
The Haijun Code session whose request triggered the exchange, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).
target: string
The credential's configured target, e.g. "aws" or "gcp".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
credentials_expire_at: optional string or null
When the exchanged cloud credentials expire. Unset when the cloud provider did not return a lifetime; such credentials were used for the single triggering request and not cached.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
slack_threads: optional array of object
The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.
channel_id: string
The Slack channel ID, e.g. "C0123ABCDE".
enterprise_id: string
The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.
team_id: string
The Slack workspace (team) ID, e.g. "T0123ABCDE".
thread_ts: string
The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.
CcrAgentProxyJuglowOidcTokenMinted object
The Haijun Code agent proxy minted a short-lived identity token for an juglow_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.
type: optional "ccr_agent_proxy_juglow_oidc_token_minted"
default: ccr_agent_proxy_juglow_oidc_token_minted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The Haijun Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.
audience: string
The minted token's audience: the fixed token-exchange audience for the "aws" target, the credential row's Google workload identity pool provider URL for the "gcp" target, or the row's configured audience for the "direct" target.
credential_id: string
The credential row the token was minted for, e.g. "apc_01HX...".
issuance_path: "broker_report" or "direct" or "proxy_record" or "unspecified"
Which record of the issuance this event is. Unspecified on events published before this field existed.
"broker_report"
"direct"
"proxy_record"
"unspecified"
mint_jti: string
The identifier of the mint attempt, a bare UUID. One mint through the Haijun Tag mint broker produces two minted events that carry the same value, the broker's own report and the agent proxy's record. A reader counts issuances from the broker's reports by distinct report_id, and several distinct reports that share one mint_jti are the accepted mints of a replayed token. Empty on events for mints that did not travel through the broker.
profile_id: string
The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
report_id: string
The identity of the mint broker's report itself, a bare UUID. The broker mints it once per report and delivery retries repeat it, so several events carrying one report_id are duplicates of one report and collapse to one issuance. Present on broker_report events only.
session_id: string
The Haijun Code session whose request triggered the mint, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).
target: string
The credential's configured target, e.g. "aws", "gcp", or "direct".
test_mint: string
Set when the token was minted by the gateway verification test that runs while an admin registers a custom-gateway audience: "wrong_subject" for the probe token the gateway must reject, "right_subject" for the control token it must accept. Empty for tokens minted for live sessions.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
slack_threads: optional array of object
The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.
channel_id: string
The Slack channel ID, e.g. "C0123ABCDE".
enterprise_id: string
The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.
team_id: string
The Slack workspace (team) ID, e.g. "T0123ABCDE".
thread_ts: string
The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.
token_expires_at: optional string or null
When the minted token expires.
format: date-time
CcrAgentProxyCredentialCreated object
A Haijun Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Haijun Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.
type: optional "ccr_agent_proxy_credential_created"
default: ccr_agent_proxy_credential_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
The credential that was created, e.g. "apc_01HX...".
credential_type: string
The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".
display_name: string
The credential's display name.
host_constraint_truncated: boolean
Whether host_constraint was capped and omits some of the configured host name patterns.
profile_id: string
The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
authorization_basis: optional object or null
How the actor was authorized to create this credential. Absent on system-initiated operations and on credentials created via a provisioning link.
slack_channel_id: string
The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
slack_enterprise_id: string
The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
slack_team_id: string
The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
via_entitlement_leg: boolean
True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
via_full_manage: boolean
True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.
granting_role_ids: optional array of string
The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).
via_account_assignment: optional boolean or null
True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
created_at: optional string
When this activity occurred.
format: date-time
host_constraint: optional array of string
The host name patterns the credential may be sent to, e.g. "api.example.com" or "*.example.com". At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyCredentialDeleted object
A Haijun Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.
type: optional "ccr_agent_proxy_credential_deleted"
default: ccr_agent_proxy_credential_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
The credential that was deleted, e.g. "apc_01HX...".
profile_id: string
The agent proxy profile the credential belonged to, e.g. "capp_01HX...". Carried so the deletion can be correlated with the profile's other audit events after the credential row no longer exists.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
authorization_basis: optional object or null
How the actor was authorized to delete this credential.
slack_channel_id: string
The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
slack_enterprise_id: string
The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
slack_team_id: string
The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
via_entitlement_leg: boolean
True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
via_full_manage: boolean
True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.
granting_role_ids: optional array of string
The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).
via_account_assignment: optional boolean or null
True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyCredentialRotated object
A Haijun Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.
type: optional "ccr_agent_proxy_credential_rotated"
default: ccr_agent_proxy_credential_rotated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
The replacement credential, e.g. "apc_01HX...".
credential_type: string
The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".
destinations_repointed: number
The number of agent proxy destinations that referenced the old credential and now reference the replacement.
display_name: string
The credential's display name.
previous_credential_id: string
The credential that was replaced, e.g. "apc_01HX...".
profile_id: string
The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
rules_repointed: number
The number of agent proxy rules that referenced the old credential and now reference the replacement.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
authorization_basis: optional object or null
How the actor was authorized to rotate this credential. Absent on automatic rotations initiated by the system rather than by a user.
slack_channel_id: string
The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
slack_enterprise_id: string
The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
slack_team_id: string
The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
via_entitlement_leg: boolean
True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
via_full_manage: boolean
True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.
granting_role_ids: optional array of string
The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).
via_account_assignment: optional boolean or null
True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyCredentialUpdated object
A Haijun Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.
type: optional "ccr_agent_proxy_credential_updated"
default: ccr_agent_proxy_credential_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
The credential that was updated, e.g. "apc_01HX...".
display_name: string
The credential's display name after the update.
host_constraint_truncated: boolean
Whether host_constraint was capped and omits some of the configured host name patterns.
profile_id: string
The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
authorization_basis: optional object or null
How the actor was authorized to update this credential.
slack_channel_id: string
The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
slack_enterprise_id: string
The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
slack_team_id: string
The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
via_entitlement_leg: boolean
True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
via_full_manage: boolean
True when the actor held the organization-wide Haijun Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel haijun_tag_channel:manage permission or, when via_account_assignment is true, via a direct channel-manager assignment.
granting_role_ids: optional array of string
The tagged IDs of the custom roles that granted the actor the per-channel haijun_tag_channel:manage permission, e.g. "rbac_role_01HX...". Empty when via_full_manage is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when via_account_assignment is true (no role stands behind a direct assignment).
via_account_assignment: optional boolean or null
True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, via_full_manage and via_entitlement_leg are false and granting_role_ids is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
created_at: optional string
When this activity occurred.
format: date-time
host_constraint: optional array of string
The host name patterns the credential may be sent to after the update, e.g. "api.example.com" or "*.example.com". Populated only when the update changed them. At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updated_fields: optional array of string
Names of the settings included in the update: "display_name", "host_constraint".
CcrAgentProxyDestinationDeleted object
An agent proxy destination was deleted.
type: optional "ccr_agent_proxy_destination_deleted"
default: ccr_agent_proxy_destination_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_with_profile: boolean
True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyDestination call.
destination_id: string
The destination that was deleted, e.g. "apd_01HX...".
profile_id: string
The agent proxy profile the destination belonged to, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
cascade_trigger_credential_id: optional string or null
Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the destination's client_tls_credential was the deleted credential). Unset for a direct DeleteAgentProxyDestination call and for the profile-delete cascade (see deleted_with_profile).
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyNetworkEventsListed object
A Haijun Code network activity export was accessed for the given hour.
type: optional "ccr_agent_proxy_network_events_listed"
default: ccr_agent_proxy_network_events_listed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
failed: boolean
True when the export request did not complete successfully.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
hour: optional string or null
The UTC hour that was exported.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProfileBound object
A Haijun Code agent proxy profile was bound to a scope, applying its policy to Haijun Code sessions in that scope.
type: optional "ccr_agent_proxy_profile_bound"
default: ccr_agent_proxy_profile_bound
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
profile_id: string
The profile that was bound, e.g. "capp_01HX...".
scope_id: string
The identifier of the scope the profile was bound to.
scope_kind: string
The kind of scope the profile was bound to: "organization", "environment", "account", or "agent".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProfileCreated object
A Haijun Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.
type: optional "ccr_agent_proxy_profile_created"
default: ccr_agent_proxy_profile_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
display_name: string
The profile's display name at creation time.
profile_id: string
The profile that was created, e.g. "capp_01HX...".
slug: string
The profile's URL-safe identifier, unique within the organization.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
github_access: optional array of object
The GitHub repository access the profile grants, one entry per GitHub App installation. Empty when the profile grants no GitHub access.
access_mode: string
How repository access is granted: "none" (no access), "list" (exactly the repositories in repos), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.
github_installation_id: number
The GitHub App installation the access applies to.
repo_count: number
The total number of repositories granted, including any omitted from repos.
repos_truncated: boolean
Whether repos was capped and omits some of the granted repositories.
ghe_configuration_id: optional number or null
The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.
repo_ids: optional array of number
The numeric GitHub repository IDs the profile grants access to, in the same order as repos (and subject to the same 100-entry cap). These IDs are the authoritative identity of the granted repositories — access is enforced against them, not against the display names in repos.
repos: optional array of string
Repository names (owner/name) the profile grants access to, populated when access_mode is "list". Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids are the authoritative identity of the granted repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when the granted set is larger.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProfileDeleted object
A Haijun Code agent proxy profile was deleted, removing its policy from everything it was bound to.
type: optional "ccr_agent_proxy_profile_deleted"
default: ccr_agent_proxy_profile_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_credential_count: number
Number of credentials deleted together with the profile — deleting a profile also deletes the credentials attached to it. Each deleted credential additionally emits its own ccr_agent_proxy_credential_deleted activity, at most 100 per profile deletion. Best-effort: when deleted_credentials_unknown is true the count could not be determined and 0 here does not mean the profile had no credentials.
deleted_credentials_unknown: boolean
Whether the number of credentials deleted with the profile could not be determined. When true, deleted_credential_count is 0 and no per-credential deletion activities were emitted, even though the deletion may have destroyed credentials.
deleted_destination_count: number
Number of destinations deleted together with the profile. Each deleted destination additionally emits its own ccr_agent_proxy_destination_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_destinations_unknown is true the count could not be determined and 0 here does not mean the profile had no destinations.
deleted_destinations_unknown: boolean
Whether the number of destinations deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.
deleted_rule_count: number
Number of rules deleted together with the profile. Each deleted rule additionally emits its own ccr_agent_proxy_rule_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_rules_unknown is true the count could not be determined and 0 here does not mean the profile had no rules.
deleted_rules_unknown: boolean
Whether the number of rules deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.
profile_id: string
The profile that was deleted, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProfileUnbound object
A Haijun Code agent proxy profile was unbound from a scope, removing its policy from Haijun Code sessions in that scope.
type: optional "ccr_agent_proxy_profile_unbound"
default: ccr_agent_proxy_profile_unbound
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
profile_id: string
The profile that was unbound, e.g. "capp_01HX...".
scope_id: string
The identifier of the scope the profile was unbound from.
scope_kind: string
The kind of scope the profile was unbound from: "organization", "environment", "account", or "agent".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProfileUpdated object
A Haijun Code agent proxy profile's configuration was updated.
type: optional "ccr_agent_proxy_profile_updated"
default: ccr_agent_proxy_profile_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
profile_id: string
The profile that was updated, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
github_access_changes: optional array of object
How the profile's GitHub repository access changed, one entry per GitHub App installation whose access changed. Empty when the update did not change GitHub access.
access_mode: string
How repository access is granted after the change: "none" (no access), "list" (access is restricted to an explicit repository list — repos_added/repos_removed carry this change's delta and repo_count the post-change total), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.
github_installation_id: number
The GitHub App installation the change applies to.
repo_count: number
The total number of repositories granted after the change.
repos_truncated: boolean
Whether repos_added or repos_removed was capped and omits some of the changed repositories.
ghe_configuration_id: optional number or null
The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.
previous_access_mode: optional string or null
How repository access was granted before the change. Present only when the access mode changed.
repo_ids_added: optional array of number
The numeric GitHub repository IDs added to the granted set, in the same order as repos_added (and subject to the same 100-entry cap). These IDs are the authoritative identity of the added repositories — access is enforced against them, not against the display names in repos_added.
repo_ids_removed: optional array of number
The numeric GitHub repository IDs removed from the granted set, in the same order as repos_removed (and subject to the same 100-entry cap). These IDs are the authoritative identity of the removed repositories.
repos_added: optional array of string
Repository names (owner/name) added to the granted set. Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids_added are the authoritative identity of the added repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when more were added. Empty when the change involves "all" access, which grants every repository regardless of any explicit list.
repos_removed: optional array of string
Repository names (owner/name) removed from the granted set. Same rendering, cap, and "all" handling as repos_added; repo_ids_removed carries the authoritative identity of the removed repositories.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updated_fields: optional array of string
Names of the configuration fields included in the update, e.g. "display_name", "github_installation_permissions".
CcrAgentProxyProvisioningCredentialRejected object
An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.
type: optional "ccr_agent_proxy_provisioning_credential_rejected"
default: ccr_agent_proxy_provisioning_credential_rejected
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
The credential the member submitted, e.g. "apc_01HX...".
link_id: string
The provisioning link's identifier.
profile_id: string
The agent proxy profile the credential lived in, e.g. "capp_01HX...".
rule_id: string
The disabled rule that was deleted alongside the credential, e.g. "apr_01HX...".
submitted_by_user_id: string
The tagged account ID of the user who originally submitted the credential, e.g. "user_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProvisioningLinkEnabled object
An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.
type: optional "ccr_agent_proxy_provisioning_link_enabled"
default: ccr_agent_proxy_provisioning_link_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
The credential the member submitted, e.g. "apc_01HX...".
link_id: string
The provisioning link's identifier.
profile_id: string
The agent proxy profile the credential lives in, e.g. "capp_01HX...".
rule_id: string
The rule that was flipped to enforce, e.g. "apr_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProvisioningLinkGenerated object
An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.
type: optional "ccr_agent_proxy_provisioning_link_generated"
default: ccr_agent_proxy_provisioning_link_generated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
link_id: string
The provisioning link's identifier. Correlation only; redemption requires an org-member session, so this is not a bearer credential.
profile_id: string
The agent proxy profile the submitted credential will be created in, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProvisioningLinkRevoked object
An organization owner revoked an unfilled agent proxy provisioning link.
type: optional "ccr_agent_proxy_provisioning_link_revoked"
default: ccr_agent_proxy_provisioning_link_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
link_id: string
The provisioning link's identifier.
profile_id: string
The agent proxy profile the link targeted, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyProvisioningLinkSubmitted object
A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.
type: optional "ccr_agent_proxy_provisioning_link_submitted"
default: ccr_agent_proxy_provisioning_link_submitted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
The credential that was created, e.g. "apc_01HX...".
credential_type: string
The kind of credential, e.g. "bearer" or "basic".
link_id: string
The provisioning link's identifier.
profile_id: string
The agent proxy profile the credential was created in, e.g. "capp_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
host_constraint: optional array of string
The host name patterns the credential may be sent to.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyRuleCreated object
An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.
type: optional "ccr_agent_proxy_rule_created"
default: ccr_agent_proxy_rule_created
action: "allow" or "deny" or "require_approval" or "unspecified"
What the rule does with a matching request.
"allow"
"deny"
"require_approval"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
has_condition: boolean
Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.
hosts_truncated: boolean
Whether hosts was capped and omits some of the configured host name patterns.
injects_credential: boolean
Whether the rule adds a managed credential to the requests it allows.
mode: "disabled" or "enforce" or "shadow" or "unspecified"
Whether the rule is enforced, only observed, or switched off.
"disabled"
"enforce"
"shadow"
"unspecified"
path_pattern_count: number
How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches; 0 when the rule matches every path.
ports_truncated: boolean
Whether ports was capped and omits some of the configured ports.
priority: number
Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.
profile_id: string
The agent proxy profile the rule belongs to, e.g. "capp_01HX...".
protocol: "http" or "mysql" or "postgres" or 3 more
The kind of connection the rule applies to.
"http"
"mysql"
"postgres"
"ssh"
"tcp"
"unspecified"
rule_id: string
The rule that was created, e.g. "apr_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
hosts: optional array of string
The host name patterns the rule matches, in canonical form (lowercase, internationalized names in their ASCII encoding), e.g. "api.example.com" or "*.example.com". At most 100 entries are included; hosts_truncated indicates when the configured set is larger.
injected_credential_id: optional string or null
The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.
methods: optional array of string
The HTTP methods the rule matches, e.g. GET. Empty when the rule matches every method.
mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more
The kinds of change the rule makes to the requests it allows, each listed once.
"inject_credential"
"route_to"
"set_header"
"strip_header"
"unspecified"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ports: optional array of number
The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.
route_to_destination_id: optional string or null
The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.
CcrAgentProxyRuleDeleted object
An agent proxy rule was deleted.
type: optional "ccr_agent_proxy_rule_deleted"
default: ccr_agent_proxy_rule_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_with_profile: boolean
True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyRule call or a provisioning-link reject (RejectAgentProxyProvisionedCredential) — the reject case also emits CcrAgentProxyProvisioningCredentialRejected with the same rule_id in the same batch.
profile_id: string
The agent proxy profile the rule belonged to, e.g. "capp_01HX...".
rule_id: string
The rule that was deleted, e.g. "apr_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
cascade_trigger_credential_id: optional string or null
Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the rule inject_credential-referenced the deleted credential). Unset for a direct DeleteAgentProxyRule call, for the profile-delete cascade (see deleted_with_profile), and for a provisioning-link reject that removed the provisioned rule.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentProxyRuleUpdated object
An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.
type: optional "ccr_agent_proxy_rule_updated"
default: ccr_agent_proxy_rule_updated
action: "allow" or "deny" or "require_approval" or "unspecified"
What the rule does with a matching request.
"allow"
"deny"
"require_approval"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
has_condition: boolean
Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.
hosts_truncated: boolean
Whether hosts was capped and omits some of the configured host name patterns.
injects_credential: boolean
Whether the rule adds a managed credential to the requests it allows.
mode: "disabled" or "enforce" or "shadow" or "unspecified"
Whether the rule is enforced, only observed, or switched off.
"disabled"
"enforce"
"shadow"
"unspecified"
path_pattern_count: number
How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches after the update; 0 when the rule matches every path.
ports_truncated: boolean
Whether ports was capped and omits some of the configured ports.
priority: number
Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.
profile_id: string
The agent proxy profile the rule belongs to, e.g. "capp_01HX...".
protocol: "http" or "mysql" or "postgres" or 3 more
The kind of connection the rule applies to.
"http"
"mysql"
"postgres"
"ssh"
"tcp"
"unspecified"
rule_id: string
The rule that was updated, e.g. "apr_01HX...".
version: number
The rule's version after the update; it increases by one on every update.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
hosts: optional array of string
The host name patterns the rule matches after the update, in canonical form (lowercase, internationalized names in their ASCII encoding). At most 100 entries are included; hosts_truncated indicates when the configured set is larger.
injected_credential_id: optional string or null
The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.
methods: optional array of string
The HTTP methods the rule matches after the update, e.g. GET. Empty when the rule matches every method.
mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more
The kinds of change the rule makes to the requests it allows after the update, each listed once.
"inject_credential"
"route_to"
"set_header"
"strip_header"
"unspecified"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ports: optional array of number
The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.
route_to_destination_id: optional string or null
The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.
CcrAgentSlackAccessScopeCreated object
A Haijun Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.
type: optional "ccr_agent_slack_access_scope_created"
default: ccr_agent_slack_access_scope_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was granted access, e.g. "cagt_01HX...".
can_write: boolean
Whether the grant includes permission to post messages in the channel, in addition to reading it.
slack_channel_id: string
The Slack channel the agent was granted access to, e.g. "C01ABC...". Empty when the grant covers the entire workspace.
slack_team_id: string
The Slack workspace containing the channel, e.g. "T01ABC...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentSlackAccessScopeDeleted object
A Haijun Code agent's access to an additional Slack channel was revoked.
type: optional "ccr_agent_slack_access_scope_deleted"
default: ccr_agent_slack_access_scope_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent whose access was revoked, e.g. "cagt_01HX...".
slack_channel_id: string
The Slack channel the agent's access was revoked from, e.g. "C01ABC...". Empty when the revoked grant covered the entire workspace.
slack_team_id: string
The Slack workspace containing the channel, e.g. "T01ABC...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentSlackBindingCreated object
A Haijun Code agent was assigned to a Slack channel or workspace as its dedicated agent.
type: optional "ccr_agent_slack_binding_created"
default: ccr_agent_slack_binding_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent the binding was created for, e.g. "cagt_01HX...".
slack_channel_id: string
The Slack channel the agent was assigned to, e.g. "C01ABC...". Empty when the agent was assigned to the entire workspace.
slack_team_id: string
The Slack workspace the agent was assigned to, e.g. "T01ABC...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentSlackBindingDeleted object
A Haijun Code agent's assignment to a Slack channel or workspace was removed.
type: optional "ccr_agent_slack_binding_deleted"
default: ccr_agent_slack_binding_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent the binding was removed from, e.g. "cagt_01HX...".
slack_channel_id: string
The Slack channel the agent was unassigned from, e.g. "C01ABC...". Empty when the assignment covered the entire workspace.
slack_team_id: string
The Slack workspace the agent was unassigned from, e.g. "T01ABC...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrAgentUpdated object
A Haijun Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.
type: optional "ccr_agent_updated"
default: ccr_agent_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was updated, e.g. "cagt_01HX...".
default_source_urls_truncated: boolean
Whether default_source_urls was capped and omits some of the granted repositories.
omitted_source_url_count: number
Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
default_source_urls: optional array of string
The agent's default repository URLs after the update, reduced to scheme, host, and path — credentials and query parameters are never included. Populated only when the update changed them — "default_source_urls" appears in updated_fields. Empty while listed in updated_fields AND omitted_source_url_count is 0 means all default repositories were removed. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.
guest_policy: optional string or null
The agent's response policy for Slack channels that include guest users and Slack Connect channels shared with other organizations, after the update: "allow", "restrict", "channel" (the agent responds, using only that channel's own content and configuration), or "default" when the update removed the agent-specific policy so the agent inherits the surrounding default. In Slack Connect channels "allow" gives at most "channel" access. Present only when the update changed it.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
slack_alias: optional string or null
The agent's Slack trigger word after the update. Present only when the update changed it. An empty value means the agent responds to bare "@Haijun" mentions.
updated_fields: optional array of string
Names of the configuration fields included in the update, e.g. "display_name", "system_prompt_addendum", "guest_policy". Includes "is_virtual" when this update was the first administrator action on an auto-provisioned agent — a durable state change even when no other field was supplied.
CcrChannelManagerAdded object
An org owner/admin assigned an organization member to manage the Haijun-in-Slack configuration of one Slack channel.
type: optional "ccr_channel_manager_added"
default: ccr_channel_manager_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The channel's Haijun agent (cagt_...) the assignment is recorded against.
slack_channel_id: string
The Slack channel the member may now manage, e.g. "C01ABC...".
slack_team_id: string
The Slack workspace containing the channel, e.g. "T01ABC...".
user_id: string
Tagged ID of the member who was assigned.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrChannelManagerRemoved object
An org owner/admin removed an organization member's assignment to manage the Haijun-in-Slack configuration of one Slack channel.
type: optional "ccr_channel_manager_removed"
default: ccr_channel_manager_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The channel's Haijun agent (cagt_...) the assignment was recorded against.
slack_channel_id: string
The Slack channel the member managed, e.g. "C01ABC...".
slack_team_id: string
The Slack workspace containing the channel, e.g. "T01ABC...".
user_id: string
Tagged ID of the member whose assignment was removed.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrRoleChannelAssignmentDeleted object
CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).
type: optional "ccr_role_channel_assignment_deleted"
default: ccr_role_channel_assignment_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
previous_channel_count: number
Number of (team, channel) pairs the role was assigned before deletion.
role_id: string
Tagged ID of the role whose channel assignment was removed.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrRoleChannelAssignmentUpdated object
CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Haijun-in-Slack channel-manage surface.
type: optional "ccr_role_channel_assignment_updated"
default: ccr_role_channel_assignment_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
channel_count: number
Number of channels assigned after the write.
previous_channel_count: number
Number of channels assigned before the write.
role_id: string
Tagged ID of the role whose channel assignment was written.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
agent_ids: optional array of string
The channel-silo agents (cagt_...) assigned after the write. Capped at 100 entries; channel_count carries the uncapped total.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrSessionCreated object
A Haijun Code session was created. A session is one coding interaction with Haijun.
type: optional "ccr_session_created"
default: ccr_session_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The session that was created, e.g. "cse_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
agent_id: optional string or null
The Haijun Code agent attached to the session, e.g. "cagt_01HX...". Omitted when the session was created without an agent.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrSessionDeleted object
A Haijun Code session was deleted.
type: optional "ccr_session_deleted"
default: ccr_session_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The session that was deleted, e.g. "cse_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
CcrSessionUpdated object
A Haijun Code session's settings were updated.
type: optional "ccr_session_updated"
default: ccr_session_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The session that was updated, e.g. "cse_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updated_fields: optional array of string
Names of the fields included in the update, e.g. "add_tags", "remove_tags".
CcrSlackChannelJoined object
Haijun's Slack app joined a public Slack channel at an organization administrator's request.
type: optional "ccr_slack_channel_joined"
default: ccr_slack_channel_joined
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
slack_channel_id: string
The Slack channel the app joined, e.g. "C01ABC...".
slack_team_id: string
The Slack workspace containing the channel, e.g. "T01ABC...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatSettingsUpdated object
User updated the settings for a conversation.
type: optional "haijun_chat_settings_updated"
default: haijun_chat_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
Tagged ID of the conversation whose settings were updated, e.g. "haijun_chat_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_id: optional string or null
Project ID this chat belongs to, if any
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatSnapshotCreated object
User created/shared a chat snapshot.
type: optional "haijun_chat_snapshot_created"
default: haijun_chat_snapshot_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
haijun_chat_snapshot_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatSnapshotDeleted object
User deleted/unshared a chat snapshot.
type: optional "haijun_chat_snapshot_deleted"
default: haijun_chat_snapshot_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_snapshot_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_chat_id: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatSnapshotViewed object
User viewed a chat snapshot (authenticated or public/unauthenticated).
type: optional "haijun_chat_snapshot_viewed"
default: haijun_chat_snapshot_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_snapshot_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_chat_id: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactDuplicated object
A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.
type: optional "haijun_artifact_duplicated"
default: haijun_artifact_duplicated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
Tagged ID of the new artifact created by the duplication. It is owned by the actor and is independent of the source artifact.
source_haijun_artifact_id: string
Tagged ID of the artifact that was copied.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
source_haijun_artifact_version_id: optional string or null
The version of the source artifact that was copied into the new artifact.
HaijunArtifactExternalSharingPermissionUpdated object
An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
type: optional "haijun_artifact_external_sharing_permission_updated"
default: haijun_artifact_external_sharing_permission_updated
action: "allowed" or "revoked" or "unspecified"
Whether the permission was allowed or revoked.
"allowed"
"revoked"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
Tagged ID of the artifact.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactInviteAccepted object
Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by invitee_email and invitee_user_id.
type: optional "haijun_artifact_invite_accepted"
default: haijun_artifact_invite_accepted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
Tagged ID of the artifact the invitation is for.
haijun_artifact_invite_id: string
Tagged ID of the invitation that was accepted.
invitee_email: string
Email address the invitation was sent to.
invitee_user_id: string
Tagged user ID of the account outside the organization that accepted the invitation.
role: string
The access level the invitation grants, for example reader.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactInviteCreated object
A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
type: optional "haijun_artifact_invite_created"
default: haijun_artifact_invite_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
Tagged ID of the artifact the invitation is for.
haijun_artifact_invite_id: string
Tagged ID of the invitation; the same ID appears on the accepted, role-updated and revoked activities for this invitation, including a later re-invitation of the same address.
invitee_email: string
Email address the invitation was sent to.
role: string
The access level the invitation grants, for example reader.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactInviteRevoked object
A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
type: optional "haijun_artifact_invite_revoked"
default: haijun_artifact_invite_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
Tagged ID of the artifact the invitation was for.
haijun_artifact_invite_id: string
Tagged ID of the invitation that was withdrawn.
invitee_email: string
Email address the invitation was sent to.
role: string
The access level the invitation granted, for example reader.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
invitee_user_id: optional string or null
Tagged user ID of the account outside the organization that had accepted the invitation; absent when it was withdrawn before anyone accepted.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunArtifactInviteRoleUpdated object
A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
type: optional "haijun_artifact_invite_role_updated"
default: haijun_artifact_invite_role_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_artifact_id: string
Tagged ID of the artifact the invitation is for.
haijun_artifact_invite_id: string
Tagged ID of the invitation whose access level was changed.
invitee_email: string
Email address the invitation was sent to.
role: string
The access level the invitation grants after the change, for example reader.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
invitee_user_id: optional string or null
Tagged user ID of the account outside the organization that had accepted the invitation; absent while the invitation is pending.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_role: optional string or null
The access level the invitation granted before the change, for example commenter.
HaijunChatAccessFailed object
A user was denied access to a Haijun.ai chat conversation.
type: optional "haijun_chat_access_failed"
default: haijun_chat_access_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
The chat conversation the user was denied access to, e.g. "haijun_chat_01Ab...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatCreated object
User created a chat.
type: optional "haijun_chat_created"
default: haijun_chat_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
Tagged ID of the created conversation, e.g. "haijun_chat_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_id: optional string or null
Tagged ID of the project the chat was created in, if any, e.g. "haijun_proj_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatDeleted object
A user deleted a Haijun.ai chat conversation.
type: optional "haijun_chat_deleted"
default: haijun_chat_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
The chat conversation that was deleted, e.g. "haijun_chat_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_id: optional string or null
The project the chat belonged to, if any, e.g. "haijun_proj_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatDeletionFailed object
A request to delete a Haijun.ai chat conversation failed.
type: optional "haijun_chat_deletion_failed"
default: haijun_chat_deletion_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
The chat conversation the user attempted to delete, e.g. "haijun_chat_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatSyncSourceCreated object
A sync source was connected for syncing external content into Haijun chats.
type: optional "haijun_chat_sync_source_created"
default: haijun_chat_sync_source_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_sync_source_id: string
Tagged ID of the chat-scoped sync source that was created.
provider: string
The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
resource_descriptor: optional string or null
A short provider-specific identifier for the external resource that was connected, e.g. owner/repo for GitHub or a file ID for Google Drive.
HaijunChatSyncSourceDeleted object
A sync source was disconnected from Haijun chats.
type: optional "haijun_chat_sync_source_deleted"
default: haijun_chat_sync_source_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_sync_source_id: string
Tagged ID of the chat-scoped sync source that was deleted.
provider: string
The external provider backing the sync source. Always unspecified for deletion events.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatSyncSourceUpdated object
A Haijun chat sync source's configuration was updated.
type: optional "haijun_chat_sync_source_updated"
default: haijun_chat_sync_source_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_sync_source_id: string
Tagged ID of the chat-scoped sync source that was updated.
provider: string
The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
config_changed: optional boolean or null
Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
resource_descriptor: optional string or null
A short provider-specific identifier for the external resource after the update, e.g. owner/repo for GitHub or a file ID for Google Drive.
HaijunChatUpdated object
User updated the chat metadata (e.g name, model).
type: optional "haijun_chat_updated"
default: haijun_chat_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
Tagged ID of the updated conversation, e.g. "haijun_chat_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_id: optional string or null
Tagged ID of the project the chat belongs to, if any, e.g. "haijun_proj_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunChatViewed object
A user viewed a Haijun.ai chat conversation.
type: optional "haijun_chat_viewed"
default: haijun_chat_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_chat_id: string
The chat conversation that was viewed, e.g. "haijun_chat_01Ab...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_id: optional string or null
The project the chat belongs to, if any, e.g. "haijun_proj_01Ab...".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeCredentialRevoked object
A Haijun Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.
type: optional "haijun_code_credential_revoked"
default: haijun_code_credential_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_type: "runner_pool_key" or "runner_token" or "session_token" or "unspecified"
The kind of credential the revoked target identifies, when known. Subject-targeted revocations cascade to every credential delegated from the target regardless of kind; this field describes the target itself, not the full set of credentials the cascade reached. For a revocation submitted as a pasted credential the kind is best-effort and may be inaccurate; the recorded jti and the revocation itself are unaffected.
"runner_pool_key"
"runner_token"
"session_token"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
agent_id: optional string or null
The agent identity whose Haijun Code credentials were revoked, when revocation targeted every session created by an agent identity, e.g. "cagt_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
delegating_jti: optional string or null
The credential identifier whose delegated credentials were revoked (a chain revoke): every credential delegated from this one was revoked, but the credential itself was not. Distinct from jti, which records a revocation of the credential itself and its delegates.
jti: optional string or null
The unique identifier of the revoked credential, recorded in its canonical form. Revoking a runner pool key also revokes every runner and session token delegated from it. A revocation submitted as a pasted credential is recorded by that credential's identifier.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
runner_id: optional string or null
The runner whose credentials were revoked, when revocation targeted every credential delegated from the runner, e.g. "ccrunner_01HX...".
runner_pool_id: optional string or null
The runner pool whose credentials were revoked, when revocation targeted every credential delegated from the pool, e.g. "ccpool_01HX...".
session_id: optional string or null
The session whose credentials were revoked, when revocation targeted every credential delegated from the session, e.g. "cse_01HX...".
user_id: optional string or null
The user whose Haijun Code credentials were revoked, when revocation targeted every credential minted for a user. Carries the user's tagged account ID, e.g. "user_01HX..." — the only form the revocation API accepts, so the field joins against other activities' account identifiers and never carries an email.
HaijunCodeReviewConfigUpdated object
Haijun Code Review configuration was enabled/disabled for an org.
type: optional "haijun_code_review_config_updated"
default: haijun_code_review_config_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enabled: boolean
Whether code review is now enabled
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
environment_id: optional string or null
Environment used for code review
model: optional string or null
Model configured for code review
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
per_review_limit_usd: optional string or null
Per-review spend limit in USD
previous_enabled: optional boolean or null
Whether code review was enabled before the change. Absent when no configuration existed before this update.
previous_environment_id: optional string or null
Environment used for code review before the change. Absent when no configuration existed before this update or no environment was set.
previous_model: optional string or null
Model configured for code review before the change. Absent when no configuration existed before this update or no model was set.
previous_per_review_limit_usd: optional string or null
Per-review spend limit in USD before the change. Absent when no configuration existed before this update or no limit was set.
previous_show_tips: optional boolean or null
Whether tip-style pull-request comments were enabled before the change. Absent when no configuration existed before this update.
previous_verification_enabled: optional boolean or null
Whether the verification stage of code review was enabled for the organization before the change. Absent when no configuration existed before this update or no preference was set.
show_tips: optional boolean or null
Whether tip-style pull-request comments are now enabled
verification_enabled: optional boolean or null
Whether the verification stage of code review is now enabled for the organization. Absent when the organization has not set a preference and the default applies.
HaijunCodeReviewRepositoryAdded object
A repository was added to org-level Haijun Code Review configuration.
type: optional "haijun_code_review_repository_added"
default: haijun_code_review_repository_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
config_id: string
ID of the repository configuration
repo_name: string
Repository name
repo_owner: string
Repository owner (GitHub org/user)
trigger_mode: string
When code review is triggered
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeReviewRepositoryRemoved object
A repository was removed from org-level Haijun Code Review configuration.
type: optional "haijun_code_review_repository_removed"
default: haijun_code_review_repository_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
config_id: string
ID of the deleted repository configuration
repo_name: string
Repository name at deletion time
repo_owner: string
Repository owner at deletion time
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeReviewRepositoryUpdated object
A Haijun Code Review repository configuration was updated.
type: optional "haijun_code_review_repository_updated"
default: haijun_code_review_repository_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
config_id: string
ID of the repository configuration
repo_name: string
Repository name
repo_owner: string
Repository owner
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
status: optional string or null
Updated status (ACTIVE/INACTIVE)
trigger_mode: optional string or null
Updated trigger mode
HaijunCodeRunnerDeleted object
A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.
type: optional "haijun_code_runner_deleted"
default: haijun_code_runner_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
runner_id: string
The runner that was removed, e.g. "ccrunner_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
runner_pool_id: optional string or null
The pool the runner was removed from, e.g. "ccpool_01HX...".
HaijunCodeRunnerPoolCreated object
A self-hosted runner pool for Haijun Code was created.
type: optional "haijun_code_runner_pool_created"
default: haijun_code_runner_pool_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
display_name: string
The display name the pool was created with.
runner_pool_id: string
The runner pool that was created, e.g. "ccpool_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeRunnerPoolDeleted object
A self-hosted runner pool was deleted.
type: optional "haijun_code_runner_pool_deleted"
default: haijun_code_runner_pool_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
runner_pool_id: string
The runner pool that was deleted, e.g. "ccpool_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
display_name: optional string or null
The pool's display name at deletion time.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeRunnerPoolSecretMinted object
A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.
type: optional "haijun_code_runner_pool_secret_minted"
default: haijun_code_runner_pool_secret_minted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
jti: string
The minted key's unique identifier (its JWT jti claim), usable to revoke that key later.
runner_pool_id: string
The runner pool the key was minted for, e.g. "ccpool_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
expires_at: optional string or null
When the minted key expires.
format: date-time
label: optional string or null
The label the key was minted with. The key minted automatically when a pool is created carries the label "Initial key".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeRunnerPoolSessionQueueUpdated object
An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.
type: optional "haijun_code_runner_pool_session_queue_updated"
default: haijun_code_runner_pool_session_queue_updated
action: "dismissed" or "provisioning_retried" or "requeued" or "unspecified"
What changed about the session's queue state.
"dismissed"
"provisioning_retried"
"requeued"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The session whose queue state changed, e.g. "cse_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
excluded_runner_id: optional string or null
The runner the session was moved off, when action is "requeued", e.g. "ccrunner_01HX...".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
runner_pool_id: optional string or null
The runner pool whose queue the session is in, when known, e.g. "ccpool_01HX...".
HaijunCodeRunnerPoolUpdated object
A self-hosted runner pool's settings were updated.
type: optional "haijun_code_runner_pool_updated"
default: haijun_code_runner_pool_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
display_name: string
The pool's display name after the update.
runner_pool_id: string
The runner pool that was updated, e.g. "ccpool_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_display_name: optional string or null
The pool's display name before the update. Absent when the name was unchanged or the previous value was unavailable.
HaijunCodeSecurityCenterConfigUpdated object
Haijun Code Security Center scanning was enabled/disabled for an org.
type: optional "haijun_code_security_center_config_updated"
default: haijun_code_security_center_config_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enabled: boolean
Whether Security Center is now enabled
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
environment_id: optional string or null
Environment used for security scanning
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityScanCancelled object
In-flight Haijun Code Security scans were cancelled for a project.
type: optional "haijun_code_security_scan_cancelled"
default: haijun_code_security_scan_cancelled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_project_id: string
Tagged ID of the scan project
scans_cancelled: number
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityScanCreated object
A Haijun Code Security scan was started.
type: optional "haijun_code_security_scan_created"
default: haijun_code_security_scan_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_id: string
Tagged ID of the created scan
scan_project_id: string
Tagged ID of the scan project the scan belongs to
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityScanProjectMemberUpdated object
A person's access to a Haijun Code Security scan project was granted, changed, or revoked.
type: optional "haijun_code_security_scan_project_member_updated"
default: haijun_code_security_scan_project_member_updated
action: "member_added" or "member_removed" or "member_role_changed" or "unspecified"
Whether the member was granted access, had their role changed, or was revoked
"member_added"
"member_removed"
"member_role_changed"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
member_id: string
Tagged ID of the member whose access changed
scan_project_id: string
Tagged ID of the scan project
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null
How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.
"member"
"organization_admin"
"organization_share"
"owner"
"unspecified"
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
role: optional string or null
Role granted to the member (full, view_triage, or view); omitted for revocations
HaijunCodeSecurityScanProjectUpdated object
A Haijun Code Security scan project was archived, unarchived, created, or migrated to a new product experience.
type: optional "haijun_code_security_scan_project_updated"
default: haijun_code_security_scan_project_updated
action: "archived" or "created" or "migrated" or 3 more
The state change applied to the scan project.
"archived"
"created"
"migrated"
"resumed"
"unarchived"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_project_id: string
Tagged ID of the scan project
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null
How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (the project's creation, or an automated change); events recorded before this field was introduced omit it.
"member"
"organization_admin"
"organization_share"
"owner"
"unspecified"
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityScanProjectVisibilityUpdated object
A Haijun Code Security scan project was shared with the organization or made private.
type: optional "haijun_code_security_scan_project_visibility_updated"
default: haijun_code_security_scan_project_visibility_updated
action: "shared" or "unshared" or "unspecified"
Whether the project was shared with the organization or made private
"shared"
"unshared"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_project_id: string
Tagged ID of the scan project
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_level: optional string or null
Access level granted to organization members (read_only or full); only set when shared
access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null
How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.
"member"
"organization_admin"
"organization_share"
"owner"
"unspecified"
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityScanRunUpdated object
A single Haijun Code Security scan run was archived, unarchived, or resumed after a billing pause.
type: optional "haijun_code_security_scan_run_updated"
default: haijun_code_security_scan_run_updated
action: "archived" or "created" or "migrated" or 3 more
The state change applied to the scan run
"archived"
"created"
"migrated"
"resumed"
"unarchived"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_id: string
Tagged ID of the scan the request named — for archive/unarchive any scan in the run, not necessarily its canonical (run_index=0) scan; for resume, the paused scan
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityScanScheduleDeleted object
A recurring scan schedule was deleted for a Haijun Code Security project.
type: optional "haijun_code_security_scan_schedule_deleted"
default: haijun_code_security_scan_schedule_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_project_id: string
Tagged ID of the scan project
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityScanScheduleUpdated object
A recurring scan schedule was set or replaced for a Haijun Code Security project.
type: optional "haijun_code_security_scan_schedule_updated"
default: haijun_code_security_scan_schedule_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
cadence: string
scan_project_id: string
Tagged ID of the scan project
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityVulnerabilityDeleted object
A Haijun Code Security vulnerability finding was permanently deleted.
type: optional "haijun_code_security_vulnerability_deleted"
default: haijun_code_security_vulnerability_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_id: string
Tagged ID of the scan the finding belonged to
vulnerability_id: number
Numeric ID of the deleted finding, as shown in the product
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityVulnerabilityFixSessionCreated object
A Haijun Code remediation session was created for a Haijun Code Security vulnerability finding.
type: optional "haijun_code_security_vulnerability_fix_session_created"
default: haijun_code_security_vulnerability_fix_session_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_id: string
Tagged ID of the scan the finding belongs to
session_id: string
ID of the created remediation session
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null
How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved; events recorded before this field was introduced omit it.
"member"
"organization_admin"
"organization_share"
"owner"
"unspecified"
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityVulnerabilityUpdated object
A Haijun Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.
type: optional "haijun_code_security_vulnerability_updated"
default: haijun_code_security_vulnerability_updated
action: "dismissed" or "fixed" or "restored" or 2 more
The state change applied to the finding
"dismissed"
"fixed"
"restored"
"unfixed"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_id: string
Tagged ID of the scan the finding belongs to
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
dismissal_reason: optional string or null
The categorized dismissal reason (only set when the finding was dismissed)
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCodeSecurityWebhookCreated object
A Haijun Code Security outbound webhook was created.
type: optional "haijun_code_security_webhook_created"
default: haijun_code_security_webhook_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
url: string
webhook_id: string
Tagged ID of the webhook
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scan_project_id: optional string or null
Tagged ID of the scan project (null for organization-wide webhooks)
HaijunCodeSecurityWebhookDeleted object
A Haijun Code Security outbound webhook was deleted.
type: optional "haijun_code_security_webhook_deleted"
default: haijun_code_security_webhook_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
webhook_id: string
Tagged ID of the webhook
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scan_project_id: optional string or null
Tagged ID of the scan project (null for organization-wide webhooks)
HaijunCodeSecurityWebhookSecretUpdated object
The HMAC signing secret for a Haijun Code Security webhook was rotated.
type: optional "haijun_code_security_webhook_secret_updated"
default: haijun_code_security_webhook_secret_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
webhook_id: string
Tagged ID of the webhook
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scan_project_id: optional string or null
Tagged ID of the scan project (null for organization-wide webhooks)
HaijunCodeSecurityWebhookUpdated object
A Haijun Code Security outbound webhook was updated.
type: optional "haijun_code_security_webhook_updated"
default: haijun_code_security_webhook_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
webhook_id: string
Tagged ID of the webhook
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scan_project_id: optional string or null
Tagged ID of the scan project (null for organization-wide webhooks)
HaijunCodeTeamMemoryACLUpdated object
An RBAC group was added to or removed from the Haijun Code team-memory ACL.
type: optional "haijun_code_team_memory_acl_updated"
default: haijun_code_team_memory_acl_updated
action: "removed" or "set" or "unspecified"
Whether the group was set (added/updated) or removed
"removed"
"set"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the RBAC group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_level: optional string or null
Access level granted (when action=set)
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_access_level: optional string or null
Access level the group had before this change; absent when the group was not previously in the access list. For removals this is the access level that was removed.
HaijunCodeTeamMemoryUpdated object
Haijun Code team memory shared with the organization was updated.
type: optional "haijun_code_team_memory_updated"
default: haijun_code_team_memory_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_all: boolean
True when the entire team memory store for this scope was deleted in one request.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
keys_deleted: optional array of string
Withdrawn — never populated. See keys_deleted_count.
keys_deleted_count: optional number or null
Number of team memory entries removed.
keys_written: optional array of string
Withdrawn — never populated. See keys_written_count.
keys_written_count: optional number or null
Number of team memory entries created or updated.
new_checksum: optional string or null
Checksum of the team memory after this change.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_checksum: optional string or null
Checksum of the team memory before this change; null when it did not exist.
repo: optional string or null
Withdrawn — never populated.
version: optional number or null
Version number of the team memory store after this change.
HaijunCodeTeamOnboardingGuideUpdated object
A Haijun Code team onboarding guide was created, updated, or deleted.
type: optional "haijun_code_team_onboarding_guide_updated"
default: haijun_code_team_onboarding_guide_updated
action: "created" or "deleted" or "unspecified" or "updated"
The state change applied to the onboarding guide.
"created"
"deleted"
"unspecified"
"updated"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
guide_short_code: string
Short code identifying the onboarding guide — the public URL handle shown in the share link.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
guide_id: optional string or null
Tagged ID of the onboarding guide.
guide_name: optional string or null
Withdrawn — never populated.
new_checksum: optional string or null
Checksum of the guide content after this change; null when the guide was deleted.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_checksum: optional string or null
Checksum of the guide content before this change; null when the guide did not exist.
HaijunCodeUserMarketplacesUpdated object
A user's Haijun Code plugin marketplace selections were updated on Juglow servers.
type: optional "haijun_code_user_marketplaces_updated"
default: haijun_code_user_marketplaces_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_all: boolean
True when all of the user's marketplace selections were removed in one request.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
keys_deleted: optional array of string
Withdrawn — never populated. See keys_deleted_count.
keys_deleted_count: optional number or null
Number of marketplace selections removed.
keys_written: optional array of string
Withdrawn — never populated. See keys_written_count.
keys_written_count: optional number or null
Number of marketplace selections added or whose source changed.
new_value: optional string or null
Withdrawn — never populated.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional string or null
Withdrawn — never populated.
HaijunCodeUserMemoryUpdated object
A user's synced private Haijun Code memory was updated or deleted on Juglow servers.
type: optional "haijun_code_user_memory_updated"
default: haijun_code_user_memory_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_all: boolean
True when the user's entire synced memory for this scope was deleted in one request.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
keys_deleted: optional array of string
Withdrawn — never populated. See keys_deleted_count.
keys_deleted_count: optional number or null
Number of memory file paths removed.
keys_written: optional array of string
Withdrawn — never populated. See keys_written_count.
keys_written_count: optional number or null
Number of memory file paths created or updated.
new_checksum: optional string or null
Checksum of the user's synced memory after this change.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_checksum: optional string or null
Checksum of the user's synced memory before this change; null when the store did not exist.
repo: optional string or null
Withdrawn — never populated.
HaijunCodeUserPluginsUpdated object
A user's Haijun Code plugin selections — which plugins are installed and enabled — were updated on Juglow servers.
type: optional "haijun_code_user_plugins_updated"
default: haijun_code_user_plugins_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_all: boolean
True when all of the user's plugin selections were removed in one request.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
keys_deleted: optional array of string
Withdrawn — never populated. See keys_deleted_count.
keys_deleted_count: optional number or null
Number of plugin selections removed.
keys_written: optional array of string
Withdrawn — never populated. See keys_written_count.
keys_written_count: optional number or null
Number of plugin selections added or whose enabled state changed.
new_value: optional string or null
The targeted plugin's new enabled state, when a single plugin's state changed.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional string or null
The targeted plugin's previous enabled state, when a single plugin's state changed; null when the plugin did not previously exist or multiple plugins changed.
HaijunCodeUserSettingsUpdated object
A user's synced Haijun Code settings were updated or deleted on Juglow servers.
type: optional "haijun_code_user_settings_updated"
default: haijun_code_user_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deleted_all: boolean
True when the user's entire synced settings store was deleted in one request.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
keys_deleted: optional array of string
Withdrawn — never populated. See keys_deleted_count.
keys_deleted_count: optional number or null
Number of settings entries removed.
keys_written: optional array of string
Withdrawn — never populated. See keys_written_count.
keys_written_count: optional number or null
Number of settings entries created or updated.
new_checksum: optional string or null
Checksum of the user's synced settings after this change.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_checksum: optional string or null
Checksum of the user's synced settings before this change; null when the store did not exist.
HaijunEnterpriseUpgradeCreditUpdated object
An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.
type: optional "haijun_enterprise_upgrade_credit_updated"
default: haijun_enterprise_upgrade_credit_updated
action: "cancelled" or "resumed" or "unspecified"
Whether the credit was cancelled or turned back on
"cancelled"
"resumed"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunFileAccessFailed object
A user was denied access to a file in Haijun.ai.
type: optional "haijun_file_access_failed"
default: haijun_file_access_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_file_id: string
The file the user was denied access to, e.g. "haijun_file_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_artifact_id: optional string or null
The artifact the file was accessed through, if any, e.g. "haijun_artifact_01HX...".
haijun_project_id: optional string or null
The project the file was accessed through, if any, e.g. "haijun_proj_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
filename: optional string or null
Deprecated
Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.
HaijunFileExported object
A file was exported from Haijun to an external storage destination.
type: optional "haijun_file_exported"
default: haijun_file_exported
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
export_destination: "google_drive" or "unspecified"
The external destination the file was exported to.
"google_drive"
"unspecified"
filename: string
Name of the exported file.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_chat_id: optional string or null
The chat conversation the file was exported from, if the export originated in a chat, e.g. "haijun_chat_01HX...".
haijun_file_id: optional string or null
The exported file, e.g. "haijun_file_01HX...", if the file has a stored file record; files that exist only inside a session have no file ID.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunFileViewed object
A user viewed a file in Haijun.ai.
type: optional "haijun_file_viewed"
default: haijun_file_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_file_id: string
The file that was viewed, e.g. "haijun_file_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_artifact_id: optional string or null
The artifact the file was accessed through, if any, e.g. "haijun_artifact_01HX...".
haijun_project_id: optional string or null
The project the file was accessed through, if any, e.g. "haijun_proj_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
filename: optional string or null
Deprecated
Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.
HaijunPluginArchiveAccessed object
A version archive of a member-owned plugin, containing that member's own files, was downloaded.
type: optional "haijun_plugin_archive_accessed"
default: haijun_plugin_archive_accessed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
marketplace_id: string
The member's personal marketplace the plugin belongs to.
owner_user_id: string
The member who owns the plugin.
plugin_id: string
The plugin whose archive was downloaded.
plugin_version_id: string
The version whose archive was downloaded.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectSyncSourceCreated object
A sync source was connected to a Haijun project's knowledge base.
type: optional "haijun_project_sync_source_created"
default: haijun_project_sync_source_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project the sync source was connected to.
haijun_project_sync_source_id: string
Tagged ID of the per-project sync source that was created.
provider: string
The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
resource_descriptor: optional string or null
A short provider-specific identifier for the external resource that was connected, e.g. owner/repo for GitHub or a file ID for Google Drive.
HaijunProjectSyncSourceDeleted object
A sync source was disconnected from a Haijun project's knowledge base.
type: optional "haijun_project_sync_source_deleted"
default: haijun_project_sync_source_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project the sync source was disconnected from.
haijun_project_sync_source_id: string
Tagged ID of the per-project sync source that was deleted.
provider: string
The external provider backing the sync source. Always unspecified for deletion events.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectSyncSourceUpdated object
A Haijun project sync source's configuration was updated.
type: optional "haijun_project_sync_source_updated"
default: haijun_project_sync_source_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project the sync source belongs to.
haijun_project_sync_source_id: string
Tagged ID of the per-project sync source that was updated.
provider: string
The external provider backing the sync source, e.g. github, google_drive, outline, slack, salesforce, google_calendar, gmail, asana, or mcp_resources.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
config_changed: optional boolean or null
Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
resource_descriptor: optional string or null
A short provider-specific identifier for the external resource after the update, e.g. owner/repo for GitHub or a file ID for Google Drive.
HaijunUserSeatTierUpdated object
An organization member's seat tier was changed. A null previous_seat_tier means the member previously had no seat assigned; a null current_seat_tier means the seat was removed.
type: optional "haijun_user_seat_tier_updated"
default: haijun_user_seat_tier_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_email: string
Email address of the member at the time of the change.
user_id: string
Tagged ID of the member whose seat tier changed.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_seat_tier: optional string or null
The member's seat tier after this change, or null if the seat was removed.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_seat_tier: optional string or null
The member's seat tier before this change, or null if no seat was assigned.
CliPluginExecPolicyUpdated object
Admin set or cleared the per-op permission ceiling for a plugin CLI.
type: optional "cli_plugin_exec_policy_updated"
default: cli_plugin_exec_policy_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
cli_name: string
CLI name as declared by the plugin manifest
marketplace_id: string
Marketplace ID owning the plugin
op_name: string
Op name (or '*' for the per-CLI default)
plugin_id: string
Plugin ID resolved from the URL
plugin_name: string
Plugin name within its marketplace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
max_permission: optional string or null
New max_permission value ('allow' | 'ask' | 'blocked'), or null when cleared
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_max_permission: optional string or null
Max permission the op had before this change ('allow' | 'ask' | 'blocked'), or null when no policy existed for the op
HaijunCommandCreated object
Command was created.
type: optional "haijun_command_created"
default: haijun_command_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
command_id: optional string or null
command_name: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCommandDeleted object
Command was deleted.
type: optional "haijun_command_deleted"
default: haijun_command_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
command_id: optional string or null
command_name: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunCommandReplaced object
Command was replaced.
type: optional "haijun_command_replaced"
default: haijun_command_replaced
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
command_id: optional string or null
command_name: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ComplianceAPIAccessed object
Logging event auto-generated for each compliance API request.
type: optional "compliance_api_accessed"
default: compliance_api_accessed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
request_id: string
Identifier of the request, as returned in the response's request-id header
request_method: "DELETE" or "GET" or "POST" or 2 more
HTTP method of the request
"DELETE"
"GET"
"POST"
"PUT"
"unspecified"
status_code: number
HTTP status code
url: string
Full URL that was requested, including any query string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
request_body: optional string or null
Serialized JSON request body
CoworkSessionUpdated object
A Cowork session was updated.
type: optional "cowork_session_updated"
default: cowork_session_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
cowork_session_id: string
Tagged ID of the updated session, e.g. "sess_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_id: optional string or null
Tagged ID of the project the session was moved to, if any, e.g. "haijun_proj_01HX...". Absent when the session was removed from its project.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DesignProjectArtifactPublished object
A Haijun Design project's content was published as a haijun.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.
type: optional "design_project_artifact_published"
default: design_project_artifact_published
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project whose content was published, e.g. "design_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
is_public: optional boolean or null
True when the published artifact is publicly viewable after this call (anyone with the link). False when it is not — by default, a newly published artifact is visible only to the person who published it.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type: "project", "template", or "design_system".
DesignProjectCreated object
A Haijun Design project was created.
type: optional "design_project_created"
default: design_project_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
creation_method: string
How the project was created: "direct", "duplicate", "remix", or "template_from_project".
design_project_id: string
The Design project that was created, e.g. "design_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project type: "project", "template", or "design_system".
source_project_id: optional string or null
The source project this was created from, when created via duplicate, remix, or template-from-project. Unset for direct creation.
DesignProjectDeleted object
A Haijun Design project was deleted.
type: optional "design_project_deleted"
default: design_project_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project that was deleted, e.g. "design_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DesignProjectMemberAdded object
A member was granted access to a Haijun Design project.
type: optional "design_project_member_added"
default: design_project_member_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project the member was added to, e.g. "design_proj_01HX...".
principal_id: string
The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
principal_type: string
The kind of member that was added: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
role: string
The role the member was granted: "viewer", "commenter", or "editor". Access-group ("compartment") members are always view-only.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type: "project", "template", or "design_system".
DesignProjectMemberRemoved object
A member's access to a Haijun Design project was revoked.
type: optional "design_project_member_removed"
default: design_project_member_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project the member was removed from, e.g. "design_proj_01HX...".
principal_id: string
The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
principal_type: string
The kind of member that was removed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type: "project", "template", or "design_system".
DesignProjectMemberRoleUpdated object
A Haijun Design project member's role was changed.
type: optional "design_project_member_role_updated"
default: design_project_member_role_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project the member belongs to, e.g. "design_proj_01HX...".
principal_id: string
The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
principal_type: string
The kind of member whose role was changed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
role: string
The member's role after the change: "viewer", "commenter", or "editor".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_role: optional string or null
The member's role before the change.
project_type: optional string or null
The project's type: "project", "template", or "design_system".
DesignProjectPublished object
A Haijun Design template or design system was published, making it discoverable by everyone in its organization.
type: optional "design_project_published"
default: design_project_published
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project that was published, e.g. "design_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type: "template" or "design_system".
DesignProjectSharingUpdated object
A Haijun Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).
type: optional "design_project_sharing_updated"
default: design_project_sharing_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project whose sharing settings changed, e.g. "design_proj_01HX...".
new_link_permission: string
What people opening the project through its link may do after the change: "view", "comment", or "edit".
new_scope: string
Who the project link is set to work for after the change: "invited" (only the owner and individually invited members) or "org" (anyone in the project's organization, where the organization's own sharing settings allow org-wide visibility). This records the project's stored setting as changed by the actor; organization-level settings can further restrict who the link actually admits, and changes to those settings are not project events. Projects created before link sharing was restricted may also report a legacy "public" value.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_link_permission: optional string or null
What people opening the project through its link could do before the change.
previous_scope: optional string or null
Who the project link was set to work for before the change — the stored setting, with the same organization-level caveat as new_scope. May include the legacy "public" value.
project_type: optional string or null
The project's type: "project", "template", or "design_system".
DesignProjectUnpublished object
A Haijun Design template or design system was unpublished, removing it from its organization's shared gallery.
type: optional "design_project_unpublished"
default: design_project_unpublished
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project that was unpublished, e.g. "design_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type: "template" or "design_system".
DesignProjectUpdated object
A Haijun Design project's metadata was updated.
type: optional "design_project_updated"
default: design_project_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project that was updated, e.g. "design_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type after the update: "project", "template", or "design_system". Present only when the update changed it.
updated_fields: optional array of string
Names of the fields changed by this update, e.g. "name", "description", "project_type", "design_systems".
DesignProjectVersionRestored object
A Haijun Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.
type: optional "design_project_version_restored"
default: design_project_version_restored
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project that was restored, e.g. "design_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type: "project", "template", or "design_system".
DesignProjectViewed object
A Haijun Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.
This activity type is retired: project content reads are no longer recorded. Events of this type may still appear in feeds for reads that occurred while it was active.
type: optional "design_project_viewed"
default: design_project_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
design_project_id: string
The Design project whose content was read, e.g. "design_proj_01HX...".
surface: string
Which read surface recorded this open: "project" (the project was opened), "project_data" (the project's full contents were read or made readable — either a direct data read, which also includes the project's conversations when the reader's access extends to them, or a render-token request, which exposes the project's files for the token's lifetime; the two share this value and are not distinguished), "file" (one of the project's files was read), "version" (a saved version of the project's files, including their contents, was read — version-history browsing that lists names without contents is not recorded), or "export" (an authenticated export of the project's contents was requested).
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_via: optional string or null
How the viewer was authorized to open the project: "owner" (the project's owner), "member_grant" (an individually invited member), "org_link" (org-wide link sharing), "trusted_service" (an authorized agent), or "design_system_reference" (an indirect read of a design system through a project that uses it).
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
project_type: optional string or null
The project's type: "project", "template", or "design_system".
DesktopExtensionAllowlisted object
A desktop extension was added to an org's allowlist.
type: optional "desktop_extension_allowlisted"
default: desktop_extension_allowlisted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
extension_id: string
Allowlisted DXT extension ID
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DesktopExtensionBlocklisted object
A desktop extension was added to the global blocklist.
type: optional "desktop_extension_blocklisted"
default: desktop_extension_blocklisted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
extension_id: string
Blocklisted DXT extension ID
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DesktopExtensionDeleted object
A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.
type: optional "desktop_extension_deleted"
default: desktop_extension_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
extension_id: string
DXT extension ID
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
version: optional string or null
Specific version deleted (null if all versions)
DesktopExtensionRemovedFromAllowlist object
A desktop extension was removed from an org's allowlist.
type: optional "desktop_extension_removed_from_allowlist"
default: desktop_extension_removed_from_allowlist
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
extension_id: string
DXT extension ID removed from allowlist
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DesktopExtensionUnblocked object
A desktop extension was removed from the global blocklist.
type: optional "desktop_extension_unblocked"
default: desktop_extension_unblocked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
extension_id: string
Unblocked DXT extension ID
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DesktopExtensionUploaded object
A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.
type: optional "desktop_extension_uploaded"
default: desktop_extension_uploaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
extension_id: string
DXT extension ID
version: string
Version string from the manifest
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DesktopExtensionVersionUploaded object
A new version of an existing org-owned desktop extension was uploaded.
type: optional "desktop_extension_version_uploaded"
default: desktop_extension_version_uploaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
extension_id: string
DXT extension ID
version: string
Version string from the manifest
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
InferenceHooksConfigDeleted object
Inference hooks configuration was removed for the organization.
type: optional "inference_hooks_config_deleted"
default: inference_hooks_config_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
InferenceHooksConfigUpdated object
Inference hooks configuration was created or updated for the organization.
type: optional "inference_hooks_config_updated"
default: inference_hooks_config_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enabled: boolean
Whether Inference hooks enforcement is enabled after this change.
enforcement_mode: string
Whether Inference hooks inspects both prompts and responses (prompt_and_response) or prompts only (prompt_only).
fail_mode: string
Whether requests are allowed (fail_open) or blocked (fail_closed) when the Inference hooks endpoint cannot be reached.
final_verdict_timeout_ms: number
Milliseconds inference waits for the Inference hooks verdict on the response.
prompt_verdict_timeout_ms: number
Milliseconds inference waits for the Inference hooks verdict on the prompt.
webhook_url: string
The endpoint that inspected prompts and responses are sent to.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
deny_message: optional string or null
Administrator-written text shown to users at the end of the error message when a request is blocked by the organization's Inference hooks policy, as configured after this change. Null when the built-in default message is in effect; an empty string when the administrator configured an empty message, in which case no text is appended.
deny_message_enabled: optional boolean or null
Whether the organization has the appended deny message turned on, as configured after this change. When on, the administrator-written message (or the built-in default, when none is configured) is appended to the error users see when a request is blocked by the organization's Inference hooks policy; no text is appended when the administrator-written message is empty, or when this is off.
extra_header_names: optional array of string or null
Names of the custom HTTP headers attached to every Inference hooks request after this change, or null when this update did not change headers. Header values are write-only and are not recorded.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
reset_circuit_breaker: optional boolean or null
Whether this update carried an explicit request to clear the circuit breaker. A tripped breaker otherwise survives configuration updates; it also clears whenever an update enables enforcement.
rollout_percentage: optional number or null
Percentage of requests (0-100) inspected by Inference hooks after this change, or null when this update did not change it. 0 disables inspection; 100 inspects every request.
shadow_mode: optional boolean or null
Whether the organization's Inference hooks run in shadow mode after this change, or null when this update did not change it. In shadow mode, prompts are still sent to the organization's endpoint and verdicts are recorded, but requests are never blocked.
InferenceHooksSigningSecretGenerated object
A request signing secret was generated for the organization's Inference hooks configuration.
type: optional "inference_hooks_signing_secret_generated"
default: inference_hooks_signing_secret_generated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
rotated: boolean
Whether this generation replaced an existing signing secret (true) or created the organization's first one (false). Replacing a secret invalidates the previous one immediately.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
DomainClaimInitiated object
Domain capture claim initiated over personal accounts on verified domains.
type: optional "domain_claim_initiated"
default: domain_claim_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
EndUserInviteRequested object
Non-admin member submitted an invite request for a new org member.
type: optional "end_user_invite_requested"
default: end_user_invite_requested
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
invitee_email: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ExtraUsageBillingEnabled object
Usage credit billing was enabled for an organization.
type: optional "extra_usage_billing_enabled"
default: extra_usage_billing_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ExtraUsageCreditGranted object
A promotional usage credit grant was claimed.
type: optional "extra_usage_credit_granted"
default: extra_usage_credit_granted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ExtraUsageSpendLimitCreated object
Usage credit spend limit was created.
type: optional "extra_usage_spend_limit_created"
default: extra_usage_spend_limit_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
amount: optional number or null
The monthly credit limit amount in minor units (e.g. cents).
created_at: optional string
When this activity occurred.
format: date-time
is_enabled: optional boolean or null
Whether the spend limit is enabled.
limit_type: optional string or null
The type of spend limit created (e.g. organization, seat_tier, member, service, group).
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
Tagged ID of the spend limit.
user_id: optional string or null
Deprecated
Deprecated. Tagged ID of the admin who performed the action — not the target member. Use spend_limit_id to look up the target member.
ExtraUsageSpendLimitDeleted object
Usage credit spend limit was deleted.
type: optional "extra_usage_spend_limit_deleted"
default: extra_usage_spend_limit_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
Tagged ID of the spend limit.
user_id: optional string or null
Deprecated
Deprecated. Tagged ID of the admin who performed the action — not the target member. Use spend_limit_id to look up the target member.
ExtraUsageSpendLimitIncreaseRequestApproved object
A usage credit spend limit increase request was approved.
type: optional "extra_usage_spend_limit_increase_request_approved"
default: extra_usage_spend_limit_increase_request_approved
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
amount: optional number or null
The approved spend limit amount in minor units (e.g. cents).
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
requester_user_id: optional string or null
Tagged ID of the member who requested the increase, e.g. "user_01HX...".
spend_limit_id: optional string or null
Tagged ID of the member's spend limit that the approval created or updated.
spend_limit_increase_request_id: optional string or null
Tagged ID of the spend limit increase request that was approved.
ExtraUsageSpendLimitIncreaseRequestDenied object
A usage credit spend limit increase request was denied.
type: optional "extra_usage_spend_limit_increase_request_denied"
default: extra_usage_spend_limit_increase_request_denied
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
requester_user_id: optional string or null
Tagged ID of the member who requested the increase, e.g. "user_01HX...".
spend_limit_increase_request_id: optional string or null
Tagged ID of the spend limit increase request that was denied.
ExtraUsageSpendLimitUpdated object
Usage credit spend limit was updated.
type: optional "extra_usage_spend_limit_updated"
default: extra_usage_spend_limit_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
amount: optional number or null
The new monthly credit limit amount in minor units (e.g. cents).
created_at: optional string
When this activity occurred.
format: date-time
is_enabled: optional boolean or null
Whether the spend limit is enabled.
limit_type: optional string or null
The type of spend limit updated (e.g. organization, seat_tier, member, service, group).
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
Tagged ID of the spend limit.
user_id: optional string or null
Deprecated
Deprecated. Tagged ID of the admin who performed the action — not the target member. Use spend_limit_id to look up the target member.
HaijunFileDeleted object
A file was deleted.
type: optional "haijun_file_deleted"
default: haijun_file_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_file_id: string
Tagged ID of the file that was deleted, e.g. "haijun_file_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the deleted file, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunFileUploaded object
A file was uploaded.
type: optional "haijun_file_uploaded"
default: haijun_file_uploaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_file_id: string
Tagged ID of the file that was uploaded, e.g. "haijun_file_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_chat_id: optional string or null
Chat ID if known at upload time (null for the upload-then-attach flow). To find which chats a file was later attached to, use GET /v1/compliance/apps/chats/files/{haijun_file_id}.
haijun_project_id: optional string or null
Project ID if file was uploaded to a project
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the uploaded file, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GheConfigurationCreated object
Admin created a GHE configuration.
type: optional "ghe_configuration_created"
default: ghe_configuration_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
ghe_configuration_id: string
ID of the GHE configuration
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
display_name: optional string or null
Display name given to the configuration
hostname: optional string or null
Hostname of the GitHub Enterprise instance
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
port: optional number or null
Custom port, if not the HTTPS default
GheConfigurationDeleted object
Admin deleted a GHE configuration.
type: optional "ghe_configuration_deleted"
default: ghe_configuration_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
ghe_configuration_id: string
ID of the GHE configuration
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
display_name: optional string or null
Display name the configuration had when deleted
hostname: optional string or null
Hostname of the GitHub Enterprise instance
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
port: optional number or null
Custom port, if not the HTTPS default
GheConfigurationUpdated object
Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
type: optional "ghe_configuration_updated"
default: ghe_configuration_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
ghe_configuration_id: string
ID of the GHE configuration
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
custom_ca_certificate_updated: optional boolean or null
Whether the custom CA certificate was replaced in this update
display_name: optional string or null
New display name, when it changed
github_app_client_id: optional string or null
New GitHub App client ID, when it changed
github_app_client_secret_updated: optional boolean or null
Whether the GitHub App client secret was replaced in this update
github_app_id: optional number or null
New GitHub App ID, when it changed
github_app_private_key_updated: optional boolean or null
Whether the GitHub App private key was replaced in this update
hostname: optional string or null
Hostname of the GitHub Enterprise instance (immutable; included for context)
is_active: optional boolean or null
New active state, when it changed
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
port: optional number or null
New port, when it changed
previous_display_name: optional string or null
Display name before the change, when it changed
previous_github_app_client_id: optional string or null
GitHub App client ID before the change, when it changed
previous_github_app_id: optional number or null
GitHub App ID before the change, when it changed
previous_is_active: optional boolean or null
Active state before the change, when it changed
previous_port: optional number or null
Port before the change, when it changed
read_replica_hostnames_updated: optional boolean or null
Whether the read replica hostnames were replaced in this update
webhook_secret_updated: optional boolean or null
Whether the webhook secret was replaced in this update
GheUserConnected object
User connected to a GHE instance.
type: optional "ghe_user_connected"
default: ghe_user_connected
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
ghe_configuration_id: optional string or null
ID of the GHE configuration
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GheUserDisconnected object
User disconnected from a GHE instance.
type: optional "ghe_user_disconnected"
default: ghe_user_disconnected
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
ghe_configuration_id: optional string or null
ID of the GHE configuration
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GheWebhookSignatureInvalid object
Webhook signature validation failed.
type: optional "ghe_webhook_signature_invalid"
default: ghe_webhook_signature_invalid
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
ghe_configuration_id: string
ID of the GHE configuration
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunGitHubIntegrationCreated object
A GitHub integration was enabled for the organization.
type: optional "haijun_github_integration_created"
default: haijun_github_integration_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
integration_id: string
Tagged ID of the GitHub integration, e.g. "haijun_sync_source_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
enabled: optional boolean or null
Whether the integration is enabled after this change.
organization_id: optional string or null
Organization ID this activity is associated with
organization_name: optional string or null
Name of the GitHub organization the integration is connected to, when known.
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_enabled: optional boolean or null
Whether the integration was enabled before this change; null when the integration had never been configured.
repository_name: optional string or null
Name of the GitHub repository the integration is connected to, when known.
HaijunGitHubIntegrationDeleted object
A GitHub integration was disabled for the organization.
type: optional "haijun_github_integration_deleted"
default: haijun_github_integration_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
integration_id: string
Tagged ID of the GitHub integration, e.g. "haijun_sync_source_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
enabled: optional boolean or null
Whether the integration is enabled after this change.
organization_id: optional string or null
Organization ID this activity is associated with
organization_name: optional string or null
Name of the GitHub organization the integration was connected to, when known.
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_enabled: optional boolean or null
Whether the integration was enabled before this change; null when the integration had never been configured.
repository_name: optional string or null
Name of the GitHub repository the integration was connected to, when known.
HaijunGitHubIntegrationUpdated object
A GitHub integration's configuration was updated.
type: optional "haijun_github_integration_updated"
default: haijun_github_integration_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
integration_id: string
Tagged ID of the GitHub integration, e.g. "haijun_sync_source_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_name: optional string or null
Name of the GitHub organization the integration is connected to, when known.
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
repository_name: optional string or null
Name of the GitHub repository the integration is connected to, when known.
GitHubAppInstallationLinked object
An installation of the Haijun GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Haijun Code features act on that GitHub account's repositories.
type: optional "github_app_installation_linked"
default: github_app_installation_linked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
github_installation_id: number
Numeric GitHub ID of the installation that was linked
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
github_account_login: optional string or null
Login of the GitHub organization or user account the App is installed on
github_account_type: optional string or null
Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GitHubAppInstallationUnlinked object
An installation of the Haijun GitHub App was unlinked from the organization, so the organization's Haijun Code features can no longer act on that GitHub account's repositories through it.
type: optional "github_app_installation_unlinked"
default: github_app_installation_unlinked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
github_installation_id: number
Numeric GitHub ID of the installation that was unlinked
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
github_account_login: optional string or null
Login of the GitHub organization or user account the App is installed on
github_account_type: optional string or null
Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GitHubTokenImport object
A user attempted to import a personal GitHub access token for use with Haijun Code. The result field indicates the outcome of the import (imported, rejected, or failed).
type: optional "github_token_import"
default: github_token_import
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
result: "failed_internal" or "imported" or "rejected_feature_disabled" or 5 more
The outcome of the import.
"failed_internal"
"imported"
"rejected_feature_disabled"
"rejected_invalid_credential"
"rejected_missing_repo_scope"
"rejected_tenant_not_ready"
"rejected_zdr_policy"
"unspecified"
source: string
How the token was imported.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
github_username: optional string or null
The GitHub username the imported token authenticates as, when known.
granted_scopes: optional string or null
The scopes granted to the imported token, when available.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
token_fingerprint_sha256: optional string or null
Org-scoped SHA-256 of the submitted token: sha256(org_uuid || 0x00 || token), lowercase-hex-encoded, where org_uuid is the organization's UUID as a dashed lowercase string, 0x00 is a single zero byte, and token is the submitted value's raw bytes. Per-org correlation only — the same token in two orgs produces distinct fingerprints. Set only when the submitted value carries a known GitHub PAT prefix (a high-entropy token format); unset for all other submissions, including rejected non-PAT input.
GitlabConfigurationCreated object
An organization admin created a self-managed GitLab configuration for syncing plugin marketplaces.
type: optional "gitlab_configuration_created"
default: gitlab_configuration_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
gitlab_configuration_id: string
ID of the GitLab configuration
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
display_name: optional string or null
Display name given to the configuration
hostname: optional string or null
Hostname of the GitLab instance
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
port: optional number or null
Custom port, if not the HTTPS default
GitlabConfigurationDeleted object
An organization admin deleted a self-managed GitLab configuration.
type: optional "gitlab_configuration_deleted"
default: gitlab_configuration_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
gitlab_configuration_id: string
ID of the GitLab configuration
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
display_name: optional string or null
Display name the configuration had when deleted
hostname: optional string or null
Hostname of the GitLab instance
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
port: optional number or null
Custom port, if not the HTTPS default
GitlabConfigurationUpdated object
An organization admin updated a self-managed GitLab configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
type: optional "gitlab_configuration_updated"
default: gitlab_configuration_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
gitlab_configuration_id: string
ID of the GitLab configuration
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_token_updated: optional boolean or null
Whether the access token was replaced in this update
created_at: optional string
When this activity occurred.
format: date-time
custom_ca_certificate_updated: optional boolean or null
Whether the custom CA certificate was replaced in this update
display_name: optional string or null
New display name, when it changed
hostname: optional string or null
Hostname of the GitLab instance (immutable; included for context)
is_active: optional boolean or null
New active state, when it changed
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
port: optional number or null
New port, when it changed
previous_display_name: optional string or null
Display name before the change, when it changed
previous_is_active: optional boolean or null
Active state before the change, when it changed
previous_port: optional number or null
Port before the change, when it changed
HaijunGdriveIntegrationCreated object
A Google Drive integration was enabled for the organization.
type: optional "haijun_gdrive_integration_created"
default: haijun_gdrive_integration_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
integration_id: string
Tagged ID of the Google Drive integration, e.g. "haijun_sync_source_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
folder_id: optional string or null
Identifier of the Google Drive folder the integration is connected to, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunGdriveIntegrationDeleted object
A Google Drive integration was disabled for the organization.
type: optional "haijun_gdrive_integration_deleted"
default: haijun_gdrive_integration_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
integration_id: string
Tagged ID of the Google Drive integration, e.g. "haijun_sync_source_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
folder_id: optional string or null
Identifier of the Google Drive folder the integration was connected to, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunGdriveIntegrationUpdated object
A Google Drive integration's configuration was updated.
type: optional "haijun_gdrive_integration_updated"
default: haijun_gdrive_integration_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
integration_id: string
Tagged ID of the Google Drive integration, e.g. "haijun_sync_source_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
folder_id: optional string or null
Identifier of the Google Drive folder the integration is connected to, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupCreated object
A group was created (RBAC admin or SCIM provisioning).
type: optional "group_created"
default: group_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the created group
group_name: string
Name of the created group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupDeleted object
A group was deleted (RBAC admin or SCIM provisioning).
type: optional "group_deleted"
default: group_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the deleted group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupListViewed object
Admin viewed the list of RBAC groups.
type: optional "group_list_viewed"
default: group_list_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupMemberAdded object
One or more members were added to a group.
type: optional "group_member_added"
default: group_member_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
member_ids: optional array of string
Tagged IDs of the members added: user IDs, or service account IDs (svac_...) when a service account was added
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupMemberAdditionFailed object
A request to add members to a group failed. Some of the requested members may have been added before the failure.
type: optional "group_member_addition_failed"
default: group_member_addition_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
member_ids: optional array of string
Tagged IDs of the members the request attempted to add
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupMemberListViewed object
Admin viewed the members of an RBAC group.
type: optional "group_member_list_viewed"
default: group_member_list_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupMemberRemovalFailed object
A request to remove members from a group failed. Some of the requested members may have been removed before the failure.
type: optional "group_member_removal_failed"
default: group_member_removal_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
member_ids: optional array of string
Tagged IDs of the members the request attempted to remove. These are always recorded as user IDs, since whether a member was a service account is only established once its removal succeeds
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupMemberRemoved object
One or more members were removed from a group.
type: optional "group_member_removed"
default: group_member_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
member_ids: optional array of string
Tagged IDs of the members removed: user IDs, or service account IDs (svac_...) when a service account was removed. A requested member that was not in the group is listed as a user ID
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupProjectSharesRevoked object
An RBAC group's project shares in one organization were revoked in bulk.
type: optional "group_project_shares_revoked"
default: group_project_shares_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group whose project shares were revoked.
revoked_count: number
Number of distinct projects whose share with this group was revoked.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_ids: optional array of string
Tagged IDs of the projects whose share with this group was revoked.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupSkillSharesRevoked object
An RBAC group's track shares in one organization were revoked in bulk.
type: optional "group_skill_shares_revoked"
default: group_skill_shares_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group whose track shares were revoked.
revoked_count: number
Number of distinct tracks and plugins whose share with this group was revoked: the combined size of skill_ids and plugin_ids.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_ids: optional array of string
Tagged IDs of the plugins whose share with this group was revoked.
skill_ids: optional array of string
Tagged IDs of the tracks whose share with this group was revoked.
GroupUpdated object
A group was updated (RBAC admin or SCIM provisioning).
type: optional "group_updated"
default: group_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the updated group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupViewed object
A group was viewed.
type: optional "group_viewed"
default: group_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the viewed group
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
GroupVisibilityUpdated object
An RBAC group's visibility policy was updated.
type: optional "group_visibility_updated"
default: group_visibility_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
group_id: string
Tagged ID of the group whose visibility policy was updated.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
policies: optional array of object
The group's visibility policy after this update.
audience: "everyone" or "members" or "none" or "unspecified"
The audience granted this visibility facet.
"everyone"
"members"
"none"
"unspecified"
visibility_type: "discover" or "share_with" or "unspecified" or "view_members"
The visibility facet this entry grants.
"discover"
"share_with"
"unspecified"
"view_members"
previous_policies: optional array of object
The group's visibility policy before this update.
audience: "everyone" or "members" or "none" or "unspecified"
The audience granted this visibility facet.
"everyone"
"members"
"none"
"unspecified"
visibility_type: "discover" or "share_with" or "unspecified" or "view_members"
The visibility facet this entry grants.
"discover"
"share_with"
"unspecified"
"view_members"
InferenceHooksCircuitBreakerTripped object
The organization's Inference hooks circuit breaker tripped automatically: calls to the organization's Inference hooks endpoint crossed a failure threshold, and inspection was suspended to protect live traffic. While tripped, requests are handled according to the organization's failure handling setting — allowed through uninspected (fail open) or rejected (fail closed) — and no per-request Inference hooks activities are recorded. The tripped state persists until an administrator re-enables Inference hooks inspection (or explicitly resets the circuit breaker).
type: optional "inference_hooks_circuit_breaker_tripped"
default: inference_hooks_circuit_breaker_tripped
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
fail_mode: string
The failure handling in effect when the breaker tripped: "fail_open" (requests proceed uninspected) or "fail_closed" (requests are rejected).
trigger_reason: string
The kind of failure that crossed the threshold. Currently always "webhook_error": repeated failures of calls to the organization's Inference hooks endpoint.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
surface: optional string or null
The product surface of the request whose failure tripped the breaker, e.g. "haijun-ai" or "haijun-code".
InferenceHooksRequestDenied object
Inference hooks inspection denied a request. The request was blocked and no model response was produced.
type: optional "inference_hooks_request_denied"
default: inference_hooks_request_denied
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
conversation_id: optional string or null
The conversation the denied request belonged to, when available. The identifier format depends on surface.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
reference_id: optional string or null
The Inference hooks endpoint's own identifier for this scan, when it returned one — lets this denial be matched to the corresponding record in the inspection provider's console.
request_id: optional string or null
Juglow's identifier for the denied request — the same value sent to the Inference hooks endpoint as request_id.
surface: optional string or null
The product surface the request came from, e.g. "haijun-ai" or "haijun-code".
InferenceHooksRequestFailedOpen object
A request proceeded without Inference hooks inspection because a verdict could not be obtained and the organization's Inference hooks configuration is set to fail open.
type: optional "inference_hooks_request_failed_open"
default: inference_hooks_request_failed_open
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
reason: "endpoint_error" or "endpoint_timeout" or "internal_error" or "unspecified"
Why Inference hooks inspection did not return a verdict.
"endpoint_error"
"endpoint_timeout"
"internal_error"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
conversation_id: optional string or null
The conversation the request belonged to, when available. The identifier format depends on surface.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
request_id: optional string or null
Juglow's identifier for the request that proceeded uninspected. When a call to the Inference hooks endpoint was made for this request, it carried this value as request_id.
surface: optional string or null
The product surface the request came from, e.g. "haijun-ai" or "haijun-code".
IntegrationUserConnected object
User connected to an integration.
type: optional "integration_user_connected"
default: integration_user_connected
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
integration_type: optional string or null
The kind of integration the user connected, e.g. "github", "gdrive", "slack", or "mcp" for a remote MCP server.
mcp_server_id: optional string or null
ID of the connected remote MCP server, when the integration is a remote MCP server.
mcp_server_name: optional string or null
Display name of the connected remote MCP server, when the integration is a remote MCP server.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
token_vault_connect_mode: optional string or null
How a token vault credential sign-in was completed: "authorization_server" for a sign-in at an administrator-provided authorization server, or "mcp_server" for a sign-in at a tool server the organization has not registered as a connector.
IntegrationUserDisconnected object
User disconnected from an integration.
type: optional "integration_user_disconnected"
default: integration_user_disconnected
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
integration_type: optional string or null
The kind of integration the user disconnected, e.g. "github", "gdrive", "slack", or "mcp" for a remote MCP server.
mcp_server_id: optional string or null
ID of the disconnected remote MCP server, when the integration is a remote MCP server.
mcp_server_name: optional string or null
Display name of the disconnected remote MCP server, when the integration is a remote MCP server.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
InvoiceCollectionMethodUpdated object
Invoice collection method was changed.
type: optional "invoice_collection_method_updated"
default: invoice_collection_method_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
new_collection_method: optional string or null
New collection method (e.g. charge_automatically, send_invoice).
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
UserLoggedOut object
A user signed out of one or all sessions.
type: optional "user_logged_out"
default: user_logged_out
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
LtiLaunchInitiated object
LTI launch was initiated.
type: optional "lti_launch_initiated"
default: lti_launch_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
LtiLaunchSuccess object
LTI launch completed successfully.
type: optional "lti_launch_success"
default: lti_launch_success
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
LtiPlatformCreated object
Juglow staff created an LTI platform integration on behalf of an org.
type: optional "lti_platform_created"
default: lti_platform_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
lti_platform_id: string
UUID of the LTI platform
lti_platform_issuer: string
Platform issuer URL
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
LtiPlatformUpdated object
Juglow staff updated an LTI platform integration on behalf of an org.
type: optional "lti_platform_updated"
default: lti_platform_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
lti_platform_id: string
UUID of the LTI platform
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
lti_platform_issuer: optional string or null
Platform issuer URL
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
MagicLinkLoginFailed object
A magic link sign-in attempt failed.
type: optional "magic_link_login_failed"
default: magic_link_login_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
MagicLinkLoginInitiated object
A user requested a magic link sign-in email.
type: optional "magic_link_login_initiated"
default: magic_link_login_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
MagicLinkLoginSucceeded object
A user successfully signed in with a magic link email.
type: optional "magic_link_login_succeeded"
default: magic_link_login_succeeded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
auth_method: optional "magic_link" or "unspecified" or null
The method the user used to authenticate. May be absent on activities recorded before this field was introduced.
"magic_link"
"unspecified"
created_at: optional string
When this activity occurred.
format: date-time
mfa_method: optional "not_used" or "unspecified" or null
The second authentication factor performed during this login, if any. null when the second-factor status is not recorded on this event — for example, when authentication was delegated to an external identity provider and any second factor is not visible to Juglow, or when this event is one step of a multistep login whose MFA is reported on another activity. May be absent on activities recorded before this field was introduced.
"not_used"
"unspecified"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ManagedOrganizationSetupCompleted object
Managed (AWS Marketplace) organization setup was completed.
type: optional "managed_organization_setup_completed"
default: managed_organization_setup_completed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
MarketplaceCreated object
Admin created an organization marketplace.
type: optional "marketplace_created"
default: marketplace_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
marketplace_id: string
Tagged ID of the marketplace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
default_installation_preference: optional string or null
Default installation preference the marketplace was created with, applied to its plugins that have no preference of their own (required, auto_install, available or not_available); absent when none was set
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
MarketplaceDeleted object
Admin deleted an organization marketplace.
type: optional "marketplace_deleted"
default: marketplace_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
marketplace_id: string
Tagged ID of the marketplace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
MarketplaceUpdated object
Admin updated an organization marketplace.
type: optional "marketplace_updated"
default: marketplace_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
marketplace_id: string
Tagged ID of the marketplace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The setting changes applied in this update; empty for an update that changed no recorded setting (such as a sync)
type: "default_installation_preference" or "unspecified"
The marketplace setting that changed
"default_installation_preference"
"unspecified"
current_value: string
Setting value immediately after this change; empty when the setting is no longer set
previous_value: string
Setting value immediately before this change; empty when the setting was not set
MarketplaceWebhookDeleted object
Admin removed the GitHub push webhook for a marketplace.
type: optional "marketplace_webhook_deleted"
default: marketplace_webhook_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
marketplace_id: string
Tagged ID of the marketplace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
MarketplaceWebhookProvisioned object
Admin provisioned a GitHub push webhook for a marketplace.
type: optional "marketplace_webhook_provisioned"
default: marketplace_webhook_provisioned
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
marketplace_id: string
Tagged ID of the marketplace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
github_webhook_id: optional number or null
GitHub-assigned webhook ID returned by the hooks API
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
McpDirectoryServerPublished object
The organization published its approved MCP directory listing.
type: optional "mcp_directory_server_published"
default: mcp_directory_server_published
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
mcp_directory_server_id: string
Tagged ID of the MCP directory listing
mcp_directory_server_name: string
Display name of the MCP directory listing
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
McpServerCreated object
An MCP server was added to the organization.
type: optional "mcp_server_created"
default: mcp_server_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
mcp_server_id: string
Tagged ID of the MCP server
mcp_server_name: string
Display name of the MCP server
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
McpServerDeleted object
An MCP server was removed from the organization.
type: optional "mcp_server_deleted"
default: mcp_server_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
mcp_server_id: string
Tagged ID of the MCP server
mcp_server_name: string
Display name of the MCP server
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
McpServerManagedAuthTokenExchanged object
A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
type: optional "mcp_server_managed_auth_token_exchanged"
default: mcp_server_managed_auth_token_exchanged
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
managed_auth_mode: string
The managed-authorization mode used for the exchange ("haijun" or "sso").
mcp_server_id: string
The MCP server the exchange was attempted for, e.g. "mcpsrv_01Ab...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
assertion_jti: optional string or null
The JWT ID of the identity assertion presented to the authorization server, when one was minted, for cross-reference with the identity provider's own logs.
authorization_server_issuer: optional string or null
The issuer identifier of the authorization server the exchange was attempted against.
correlation_id: optional string or null
An opaque identifier customers can quote when contacting Juglow support about this exchange.
created_at: optional string
When this activity occurred.
format: date-time
error_subtype: optional string or null
A more specific classification of the failure, when available. For authorization-server rejections this is the OAuth error code the server returned (for example "invalid_grant"); for identity-provider rejections this is the error code the identity provider returned; for refused identity assertions this is a short reason code such as "not_org_member" (the user's membership in the organization could not be confirmed). Values may be added over time; treat an unrecognized value as a generic failure.
error_type: optional string or null
A short classification of why the exchange failed, when outcome is "failure". Values include "authorization_server_rejected", "authorization_server_unavailable", "identity_provider_rejected", "sso_session_invalid", "sso_connection_unsupported", "connector_scope_not_granted" and "identity_assertion_refused". The last two are refusals made before a token exchange was attempted: "connector_scope_not_granted" means the organization's role configuration grants no scopes on this connector; "identity_assertion_refused" means no identity assertion could be issued for this user and server (for example, the user's membership in the organization could not be confirmed), and is reported when access the user already had could not be renewed and, depending on the reason, when first connecting; error_subtype names the reason. Values may be added over time; treat an unrecognized value as a generic failure.
mcp_server_name: optional string or null
The MCP server's display name at the time of the exchange, when available.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
outcome: optional string or null
Whether the token exchange succeeded ("success") or was rejected ("failure").
McpServerManagedAuthUpdated object
An MCP server's enterprise managed authorization settings were set, changed, or cleared, including when they were supplied while the server was being added or edited. Fields without a "previous_" prefix describe the settings after the change and are null when the server has no managed authorization settings afterwards; "previous_" fields describe the settings before the change and are null when the server had none before (always the case for a newly added server).
type: optional "mcp_server_managed_auth_updated"
default: mcp_server_managed_auth_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
mcp_server_id: string
Tagged ID of the MCP server
mcp_server_name: string
Display name of the MCP server
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
allowed_scopes: optional string or null
The OAuth scopes managed authorization may request for the server after the change, as a space-delimited list. Null when no scope restriction is configured (or the server has no managed authorization settings); an empty string when the restriction permits no scopes.
built_in_roles_included: optional boolean or null
Whether, after the change, managed authorization extends to members who hold one of the organization's built-in roles (such as User, Admin, or Owner) rather than a custom role, in addition to members whose custom role grants it. This describes whom managed authorization reaches and is reported on every change, independent of how built-in role access is configured.
created_at: optional string
When this activity occurred.
format: date-time
individual_auth_enabled: optional boolean or null
Whether members may authorize the server individually, through their own sign-in and consent, after the change.
managed_auth_enabled: optional boolean or null
Whether managed authorization is enabled for the server after the change, so that members whose role permits it are authorized through the organization's identity provider.
managed_auth_mode: optional string or null
The managed-authorization mode after the change ("haijun" or "sso"): how the identity assertion presented on members' behalf is issued. Recorded whenever managed authorization settings exist, whether or not managed authorization is enabled; null when the server has no managed authorization settings after the change.
mcp_server_url: optional string or null
Origin (scheme, host and port, the default port omitted) of the MCP server at the time of the change; the path is never included. Null when not available.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_allowed_scopes: optional string or null
The OAuth scope restriction before the change, as a space-delimited list; null when no scope restriction was configured.
previous_built_in_roles_included: optional boolean or null
Whether managed authorization extended to members holding one of the organization's built-in roles before the change.
previous_individual_auth_enabled: optional boolean or null
Whether members could authorize the server individually before the change.
previous_managed_auth_enabled: optional boolean or null
Whether managed authorization was enabled for the server before the change.
McpServerUpdated object
An MCP server's configuration was updated.
type: optional "mcp_server_updated"
default: mcp_server_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
mcp_server_id: string
Tagged ID of the MCP server
mcp_server_name: string
Display name of the MCP server
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
McpToolPolicyUpdated object
The permission restriction for an MCP tool was set or cleared.
type: optional "mcp_tool_policy_updated"
default: mcp_tool_policy_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
mcp_server_id: string
Tagged ID of the MCP server
mcp_server_name: string
Display name of the MCP server
tool_name: string
Tool name (or '*' for the MCP-server-wide default)
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
max_permission: optional string or null
New max_permission value ('allow' | 'ask' | 'blocked'), or null when cleared
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgAnalyticsAPICapabilityUpdated object
Organization analytics_api capability was enabled or disabled.
type: optional "org_analytics_api_capability_updated"
default: org_analytics_api_capability_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Whether the analytics API capability is enabled immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Whether the analytics API capability was enabled immediately before this change
OrgBulkDeleteInitiated object
Organization bulk deletion was initiated.
type: optional "org_bulk_delete_initiated"
default: org_bulk_delete_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCapabilityGrantAdded object
A capability grant was added to a workspace or role.
type: optional "org_capability_grant_added"
default: org_capability_grant_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
grant_type: string
The type of capability grant that was added.
principal_id: string
Tagged ID of the principal the grant was added to.
principal_type: "rbac_role" or "unspecified" or "workspace"
The kind of principal the grant was added to.
"rbac_role"
"unspecified"
"workspace"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCapabilityGrantRemoved object
A capability grant was removed from a workspace or role.
type: optional "org_capability_grant_removed"
default: org_capability_grant_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
grant_type: string
The type of capability grant that was removed.
principal_id: string
Tagged ID of the principal the grant was removed from.
principal_type: "rbac_role" or "unspecified" or "workspace"
The kind of principal the grant was removed from.
"rbac_role"
"unspecified"
"workspace"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgHaijunCodeDataSharingDisabled object
Organization Haijun Code data sharing was disabled.
type: optional "org_haijun_code_data_sharing_disabled"
default: org_haijun_code_data_sharing_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgHaijunCodeDataSharingEnabled object
Organization Haijun Code data sharing was enabled.
type: optional "org_haijun_code_data_sharing_enabled"
default: org_haijun_code_data_sharing_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgHaijunCodeDesktopDisabled object
Organization Haijun Code Desktop was disabled.
type: optional "org_haijun_code_desktop_disabled"
default: org_haijun_code_desktop_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgHaijunCodeDesktopEnabled object
Organization Haijun Code Desktop was enabled.
type: optional "org_haijun_code_desktop_enabled"
default: org_haijun_code_desktop_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgHaijunCodeZeroDataRetentionDisabled object
A primary owner disabled zero data retention for Haijun Code, so Haijun Code content is retained according to the organization's data retention settings.
type: optional "org_haijun_code_zero_data_retention_disabled"
default: org_haijun_code_zero_data_retention_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgComplianceAPISettingsUpdated object
Organization compliance API settings were updated.
type: optional "org_compliance_api_settings_updated"
default: org_compliance_api_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
compliance_api_enabled: optional boolean or null
Whether the compliance API is enabled for the organization after this change.
compliance_api_logging_enabled: optional boolean or null
Whether compliance activity logging is enabled for the organization after this change.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgConnectorDomainGuardUpdated object
Enterprise admin changed whether connectors are restricted to verified domains.
type: optional "org_connector_domain_guard_updated"
default: org_connector_domain_guard_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enforced: boolean
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkActWithoutAskingModeDisabled object
The "Act without asking" mode in Cowork was disabled for the organization, so members can no longer let Haijun act without asking for approval.
type: optional "org_cowork_act_without_asking_mode_disabled"
default: org_cowork_act_without_asking_mode_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkActWithoutAskingModeEnabled object
The "Act without asking" mode in Cowork was enabled for the organization, allowing members to let Haijun act without asking for approval.
type: optional "org_cowork_act_without_asking_mode_enabled"
default: org_cowork_act_without_asking_mode_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkAgentDisabled object
Organization Cowork Agent was disabled.
type: optional "org_cowork_agent_disabled"
default: org_cowork_agent_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgCoworkAgentEnabled object
Organization Cowork Agent was enabled.
type: optional "org_cowork_agent_enabled"
default: org_cowork_agent_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgCoworkAutoModeDisabled object
The "Auto" permission mode in Cowork was disabled for the organization, so members can no longer let Haijun approve its own actions after a safety check.
type: optional "org_cowork_auto_mode_disabled"
default: org_cowork_auto_mode_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkAutoModeEnabled object
The "Auto" permission mode in Cowork was enabled for the organization, allowing members to let Haijun approve its own actions after a safety check.
type: optional "org_cowork_auto_mode_enabled"
default: org_cowork_auto_mode_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkBrowserPaneDisabled object
The in-app browser in Cowork was disabled for the organization, so Haijun can no longer open or use websites in a browser pane during members' Cowork sessions.
type: optional "org_cowork_browser_pane_disabled"
default: org_cowork_browser_pane_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkBrowserPaneEnabled object
The in-app browser in Cowork was enabled for the organization, letting Haijun open and use websites in a browser pane during members' Cowork sessions.
type: optional "org_cowork_browser_pane_enabled"
default: org_cowork_browser_pane_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkDisabled object
Organization cowork was disabled.
type: optional "org_cowork_disabled"
default: org_cowork_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgCoworkEnabled object
Organization cowork was enabled.
type: optional "org_cowork_enabled"
default: org_cowork_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgCoworkMcpAlwaysAllowDisabled object
The "Always allow" option for connector tools in Cowork was disabled for the organization, so each use of a connector tool that can make changes requires approval. Read-only connector tools are not affected by this setting.
type: optional "org_cowork_mcp_always_allow_disabled"
default: org_cowork_mcp_always_allow_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkMcpAlwaysAllowEnabled object
The "Always allow" option for connector tools in Cowork was enabled for the organization, letting members approve a connector tool that can make changes once and allow its later uses automatically. Read-only connector tools are not affected by this setting.
type: optional "org_cowork_mcp_always_allow_enabled"
default: org_cowork_mcp_always_allow_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkOtlpSettingsUpdated object
The organization's Cowork OpenTelemetry monitoring export settings were updated.
type: optional "org_cowork_otlp_settings_updated"
default: org_cowork_otlp_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
new_otlp_content_capture: optional array of string or null
The organization's content-capture settings after the change, as a sorted list of category names. An empty list means content capture is explicitly turned off. Null if the settings are not set or were not modified by this update.
new_otlp_endpoint: optional string or null
The OpenTelemetry export endpoint after the change. Credentials in the URL userinfo or query string are removed; path segments are retained. Null if the endpoint is unset or was not itself modified by this update.
new_otlp_protocol: optional string or null
The OpenTelemetry export protocol after the change. Null if the protocol is unset or was not itself modified by this update.
new_otlp_resource_attributes: optional string or null
The OpenTelemetry resource attributes after the change. Null if the attributes are unset or were not themselves modified by this update.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
otlp_headers_change: optional "cleared" or "set" or "unspecified" or null
Whether the OpenTelemetry export headers were set or cleared. 'set' is recorded for any non-empty submission, including resubmission of an unchanged value. Header values are never included.
"cleared"
"set"
"unspecified"
previous_otlp_content_capture: optional array of string or null
The organization's content-capture settings before the change, as a sorted list of category names. An empty list means content capture is explicitly turned off. Null if the settings were not previously set or were not modified by this update.
previous_otlp_endpoint: optional string or null
The OpenTelemetry export endpoint before the change. Credentials in the URL userinfo or query string are removed; path segments are retained. Null if the endpoint was previously unset or was not itself modified by this update.
previous_otlp_protocol: optional string or null
The OpenTelemetry export protocol before the change. Null if the protocol was previously unset or was not itself modified by this update.
previous_otlp_resource_attributes: optional string or null
The OpenTelemetry resource attributes before the change. Null if the attributes were previously unset or were not themselves modified by this update.
OrgCoworkRemoteDisabled object
Running Cowork in the cloud was disabled for the organization, so members can no longer run Cowork sessions in Juglow-hosted remote environments.
type: optional "org_cowork_remote_disabled"
default: org_cowork_remote_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCoworkRemoteEnabled object
Running Cowork in the cloud was enabled for the organization, allowing members to run Cowork sessions in Juglow-hosted remote environments.
type: optional "org_cowork_remote_enabled"
default: org_cowork_remote_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgCreationBlocked object
Organization creation was blocked.
type: optional "org_creation_blocked"
default: org_creation_blocked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
reason: optional string or null
"blocked" when the organization started preventing users with an email address at one of its verified domains from creating new organizations, "unblocked" when it stopped.
OrgDataExportAccessed object
Organization data export file was accessed/downloaded via signed URL.
type: optional "org_data_export_accessed"
default: org_data_export_accessed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
export_type: optional "conversations" or "unspecified" or "workbench" or null
Which data set was downloaded. Absent on records written before this field was introduced.
"conversations"
"unspecified"
"workbench"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDataExportCompleted object
Organization data export was completed.
type: optional "org_data_export_completed"
default: org_data_export_completed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
export_type: optional "conversations" or "unspecified" or "workbench" or null
Which data set was exported. Absent on records written before this field was introduced.
"conversations"
"unspecified"
"workbench"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDataExportStarted object
Organization data export was started.
type: optional "org_data_export_started"
default: org_data_export_started
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
export_type: optional "conversations" or "unspecified" or "workbench" or null
Which data set was exported. Absent on records written before this field was introduced.
"conversations"
"unspecified"
"workbench"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scope: optional "member_own_data" or "organization" or "unspecified" or null
Breadth of the export — the whole organization, or only the requesting member's own data. Absent on records written before this field was introduced.
"member_own_data"
"organization"
"unspecified"
OrgDataResidencyUpdated object
The organization's inference data residency settings were updated.
type: optional "org_data_residency_updated"
default: org_data_residency_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "allowed_inference_geos" or "default_inference_geo" or "unspecified"
The data residency setting that changed
"allowed_inference_geos"
"default_inference_geo"
"unspecified"
current_value: optional string or null
Setting value immediately after this change. For allowed_inference_geos: a comma-separated list of geo codes (e.g. 'global,us'), or the literal 'unrestricted'. For default_inference_geo: a single geo code.
previous_value: optional string or null
Setting value immediately before this change. For allowed_inference_geos: a comma-separated list of geo codes (e.g. 'global,us'), or the literal 'unrestricted'. For default_inference_geo: a single geo code.
OrgDeletedViaBulk object
Organization was deleted via bulk operation.
type: optional "org_deleted_via_bulk"
default: org_deleted_via_bulk
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDeletionRequested object
Organization deletion was requested.
type: optional "org_deletion_requested"
default: org_deletion_requested
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDirectoryResyncCompleted object
Organization directory resync completed successfully.
type: optional "org_directory_resync_completed"
default: org_directory_resync_completed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resync_uuid: string
UUID identifying the directory resync run that completed.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDirectoryResyncFailed object
Organization directory resync failed.
type: optional "org_directory_resync_failed"
default: org_directory_resync_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resync_uuid: string
UUID identifying the directory resync run that failed.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDirectoryResyncStarted object
Organization directory resync was started asynchronously.
type: optional "org_directory_resync_started"
default: org_directory_resync_started
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resync_uuid: string
UUID identifying this directory resync run
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
sync_destinations: optional array of string
Sync destinations the resync targets (for example, accounts and rbac)
OrgDirectorySyncActivated object
Organization directory sync was activated.
type: optional "org_directory_sync_activated"
default: org_directory_sync_activated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDirectorySyncAddInitiated object
Organization directory sync setup was initiated.
type: optional "org_directory_sync_add_initiated"
default: org_directory_sync_add_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDirectorySyncDeleted object
Organization directory sync was deleted.
type: optional "org_directory_sync_deleted"
default: org_directory_sync_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDiscoverabilityDisabled object
Admin disabled organization discoverability.
type: optional "org_discoverability_disabled"
default: org_discoverability_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDiscoverabilityEnabled object
Admin enabled organization discoverability.
type: optional "org_discoverability_enabled"
default: org_discoverability_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDiscoverabilitySettingsUpdated object
Admin updated organization discoverability settings.
type: optional "org_discoverability_settings_updated"
default: org_discoverability_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDomainAddInitiated object
Organization domain verification was initiated.
type: optional "org_domain_add_initiated"
default: org_domain_add_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDomainRemoved object
Organization domain was removed.
type: optional "org_domain_removed"
default: org_domain_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
domain: optional string or null
The email domain that was removed from the organization, e.g. "example.com".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgDomainVerified object
Organization domain was verified.
type: optional "org_domain_verified"
default: org_domain_verified
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
domain: optional string or null
The email domain that was verified for the organization, e.g. "example.com".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgExternalKeyCreated object
A CMEK external key config was created.
type: optional "org_external_key_created"
default: org_external_key_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
external_key_id: string
Tagged ID of the created external key config
provider: "aws" or "azure" or "gcp" or "unspecified"
KMS provider backing the key
"aws"
"azure"
"gcp"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgExternalKeyDeleted object
A CMEK external key config was deleted.
type: optional "org_external_key_deleted"
default: org_external_key_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
external_key_id: string
Tagged ID of the deleted external key config
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgExternalKeyUpdated object
A CMEK external key config was updated.
type: optional "org_external_key_updated"
default: org_external_key_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
external_key_id: string
Tagged ID of the updated external key config
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "display_name" or "geo" or "provider_config" or "unspecified"
The external key config field that changed
"display_name"
"geo"
"provider_config"
"unspecified"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
OrgExternalKeyValidated object
A CMEK external key config was validated against the customer's KMS.
type: optional "org_external_key_validated"
default: org_external_key_validated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
external_key_id: string
Tagged ID of the validated external key config
validation_result: "failure" or "success" or "unspecified"
Outcome of the encrypt/decrypt roundtrip
"failure"
"success"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgHipaaSelfServeEnabled object
A primary owner click-accepted the BAA and enabled HIPAA protections for the organization via the self-serve flow.
type: optional "org_hipaa_self_serve_enabled"
default: org_hipaa_self_serve_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
baa_content_hash: string
SHA-256 digest (hex) of the Business Associate Agreement that was accepted.
baa_version_label: string
Version label of the Business Associate Agreement that was accepted, e.g. "2026-05-06".
setup_guide_content_hash: string
SHA-256 digest (hex) of the HIPAA setup guide that was current when HIPAA protections were enabled.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgIPRestrictionCreated object
Organization IP restriction was created.
type: optional "org_ip_restriction_created"
default: org_ip_restriction_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgIPRestrictionDeleted object
Organization IP restriction was deleted.
type: optional "org_ip_restriction_deleted"
default: org_ip_restriction_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgIPRestrictionUpdated object
Organization IP restriction was updated.
type: optional "org_ip_restriction_updated"
default: org_ip_restriction_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgInviteLinkDisabled object
Organization invite link was disabled.
type: optional "org_invite_link_disabled"
default: org_invite_link_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgInviteLinkGenerated object
Organization invite link was generated.
type: optional "org_invite_link_generated"
default: org_invite_link_generated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgInviteLinkRegenerated object
Organization invite link was regenerated (previous link invalidated).
type: optional "org_invite_link_regenerated"
default: org_invite_link_regenerated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgInviteViewed object
An organization invite was viewed.
type: optional "org_invite_viewed"
default: org_invite_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
invite_id: string
Tagged ID of the viewed invite
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgInvitesListed object
Organization invites were listed.
type: optional "org_invites_listed"
default: org_invites_listed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgJoinProposalDecided object
Approve or reject decision on a parent-org join proposal.
type: optional "org_join_proposal_decided"
default: org_join_proposal_decided
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
approved: boolean
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgJoinRequestApproved object
Admin approved a join request.
type: optional "org_join_request_approved"
default: org_join_request_approved
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgJoinRequestCreated object
User requested to join an organization.
type: optional "org_join_request_created"
default: org_join_request_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgJoinRequestDismissed object
Admin dismissed a join request.
type: optional "org_join_request_dismissed"
default: org_join_request_dismissed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgJoinRequestInstantApproved object
Join request was instantly approved.
type: optional "org_join_request_instant_approved"
default: org_join_request_instant_approved
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgJoinRequestsBulkDismissed object
Admin bulk-dismissed join requests.
type: optional "org_join_requests_bulk_dismissed"
default: org_join_requests_bulk_dismissed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgMagicLinkSecondFactorToggled object
Organization magic link second factor was toggled.
type: optional "org_magic_link_second_factor_toggled"
default: org_magic_link_second_factor_toggled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enabled: boolean
Whether members signing in with SSO must also complete a magic link as a second factor, after this change.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgMemberInvitesDisabled object
Admin disabled member invites for the organization.
type: optional "org_member_invites_disabled"
default: org_member_invites_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgMemberInvitesEnabled object
Admin enabled member invites for the organization.
type: optional "org_member_invites_enabled"
default: org_member_invites_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgMembersExported object
Organization members list was exported as CSV.
type: optional "org_members_exported"
default: org_members_exported
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgModelDefaultUpdated object
An organization or role default model setting was changed by an administrator.
type: optional "org_model_default_updated"
default: org_model_default_updated
action: "cleared" or "set" or "unspecified"
Whether the default model was set or cleared
"cleared"
"set"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
override_user_selection: boolean
Whether the default is enforced as a fixed default, resetting members' own model selections at the start of each new conversation
principal_id: string
Tagged ID of the organization or role the default applies to
principal_type: "org" or "rbac_role" or "unspecified"
Whether the default applies to the whole organization or to a single role
"org"
"rbac_role"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
default_model: optional string or null
The model set as the default, when the action is set
model_access: optional array of object
The per-model access overrides set for this principal; absent when no overrides are configured
api_name: string
The model the decision applies to
enabled: boolean
Whether members with this principal may select the model
max_effort_level: optional string or null
The highest effort level members may select for this model, when capped
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgParentJoinProposalCreated object
Organization parent join proposal was created.
type: optional "org_parent_join_proposal_created"
default: org_parent_join_proposal_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgParentSearchPerformed object
Organization parent search was performed.
type: optional "org_parent_search_performed"
default: org_parent_search_performed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSSOAddInitiated object
Organization SSO setup was initiated.
type: optional "org_sso_add_initiated"
default: org_sso_add_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSSOConnectionActivated object
Organization SSO connection was activated.
type: optional "org_sso_connection_activated"
default: org_sso_connection_activated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
connection_id: optional string or null
Identifier of the SSO connection that was activated.
connection_type: optional string or null
The type of SSO connection that was activated, e.g. "OktaSAML" or "GenericOIDC".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSSOConnectionDeactivated object
Organization SSO connection was deactivated.
type: optional "org_sso_connection_deactivated"
default: org_sso_connection_deactivated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
connection_id: optional string or null
Identifier of the SSO connection that was deactivated.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSSOConnectionDeleted object
Organization SSO connection was deleted.
type: optional "org_sso_connection_deleted"
default: org_sso_connection_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
connection_id: optional string or null
Identifier of the SSO connection that was deleted.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSSOGroupRoleMappingsUpdated object
Organization SSO group role mappings were updated.
type: optional "org_sso_group_role_mappings_updated"
default: org_sso_group_role_mappings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSSOProvisioningModeChanged object
Organization SSO provisioning mode was changed.
type: optional "org_sso_provisioning_mode_changed"
default: org_sso_provisioning_mode_changed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
new_mode: optional string or null
The SSO provisioning mode after this change, e.g. "LOGIN_ONLY", "JIT_PERMISSIVE", "JIT_ADVANCED", "SCIM_PERMISSIVE", or "SCIM_ADVANCED".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_mode: optional string or null
The SSO provisioning mode before this change, e.g. "LOGIN_ONLY", "JIT_PERMISSIVE", "JIT_ADVANCED", "SCIM_PERMISSIVE", or "SCIM_ADVANCED".
OrgSSOScimWelcomeEmailToggled object
Organization SCIM-provisioned welcome email was toggled.
type: optional "org_sso_scim_welcome_email_toggled"
default: org_sso_scim_welcome_email_toggled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enabled: boolean
Whether the SCIM welcome email is enabled after this change.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_enabled: optional boolean or null
Whether the SCIM welcome email was enabled before this change.
OrgSSOSeatTierAssignmentToggled object
Organization SSO seat tier assignment was toggled.
type: optional "org_sso_seat_tier_assignment_toggled"
default: org_sso_seat_tier_assignment_toggled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enabled: boolean
Whether SSO seat tier assignment is enabled after this change.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_enabled: optional boolean or null
Whether SSO seat tier assignment was enabled before this change.
OrgSSOSeatTierMappingsUpdated object
Organization SSO seat tier mappings were updated.
type: optional "org_sso_seat_tier_mappings_updated"
default: org_sso_seat_tier_mappings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_mappings: optional array of object or null
Identity provider group to seat tier mappings after this change.
idp_group_name: string
Name of the identity provider group.
seat_tier: optional string or null
Seat tier assigned to members of the identity provider group, or null if the mapping assigns no seat.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_mappings: optional array of object or null
Identity provider group to seat tier mappings before this change.
idp_group_name: string
Name of the identity provider group.
seat_tier: optional string or null
Seat tier assigned to members of the identity provider group, or null if the mapping assigns no seat.
OrgSSOToggled object
Organization SSO was toggled on or off.
type: optional "org_sso_toggled"
default: org_sso_toggled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enabled: boolean
Whether SSO login is enforced after this change.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSyncDeletingSynchronizedFilesStarted object
Organization started deleting synchronized files.
type: optional "org_sync_deleting_synchronized_files_started"
default: org_sync_deleting_synchronized_files_started
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgSyncSynchronizedFilesDeleted object
Organization synchronized files were deleted.
type: optional "org_sync_synchronized_files_deleted"
default: org_sync_synchronized_files_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgTaintAdded object
A taint was added to an organization.
type: optional "org_taint_added"
default: org_taint_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
taint: optional string or null
The taint that was added, for example the HIPAA taint.
workspace_id: optional string or null
Tagged ID of the workspace the taint was applied to. Unset when applied at organization scope.
OrgTaintRemoved object
A taint was removed from an organization.
type: optional "org_taint_removed"
default: org_taint_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
taint: optional string or null
The taint that was removed, for example the HIPAA taint.
OrgUserDeleted object
User was removed from organization.
type: optional "org_user_deleted"
default: org_user_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
deleted_user_email: optional string or null
Email address of the member who was removed, when known.
deleted_user_id: optional string or null
Tagged ID of the member who was removed from the organization, e.g. "user_01HX...".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgUserInviteAccepted object
Organization user invite was accepted.
type: optional "org_user_invite_accepted"
default: org_user_invite_accepted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
invite_id: optional string or null
Tagged ID of the invite that was accepted.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
rbac_group_ids: optional array of string or null
RBAC group IDs the user was added to on acceptance, as confirmed by the group service (absent on rows written before this was recorded, and when the invite carried no groups)
OrgUserInviteDeleted object
Organization user invite was deleted.
type: optional "org_user_invite_deleted"
default: org_user_invite_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
invite_id: optional string or null
Tagged ID of the invite that was deleted.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgUserInviteReSent object
Organization user invite was re-sent.
type: optional "org_user_invite_re_sent"
default: org_user_invite_re_sent
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
invited_email: optional string or null
Email address the invite was re-sent to.
invited_role: optional string or null
Role the invited user will receive on joining
invited_seat_tier: optional string or null
Seat tier the invited user will receive on joining
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgUserInviteRejected object
Organization user invite was rejected.
type: optional "org_user_invite_rejected"
default: org_user_invite_rejected
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
invite_id: optional string or null
Tagged ID of the invite that was rejected.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgUserInviteSent object
Organization user invite was sent.
type: optional "org_user_invite_sent"
default: org_user_invite_sent
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
invited_email: optional string or null
Email address the invite was sent to.
invited_rbac_group_ids: optional array of string or null
RBAC group IDs the invited user will be added to on joining
invited_role: optional string or null
Role the invited user will receive on joining.
invited_seat_tier: optional string or null
Seat tier the invited user will receive on joining
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgUserLeft object
User removed themselves from organization.
type: optional "org_user_left"
default: org_user_left
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_role: optional string or null
The role the member held in the organization before leaving, e.g. "user" or "admin".
OrgUserSharesRetained object
A member left or was removed from the organization while projects, tracks, plugins, or chats they had shared were still shared, and those shares were kept.
type: optional "org_user_shares_retained"
default: org_user_shares_retained
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resource_count: number
Number of distinct resources the member had shared that are still shared, counted up to a fixed limit, so a lower bound when truncated is true; it can exceed the number of IDs listed below.
share_count: number
Number of shares kept across those resources (one per audience a resource is shared with), counted up to the same limit, so a lower bound when truncated is true.
truncated: boolean
True when the ID lists do not include every still-shared resource or the counts stopped at their limit.
user_id: string
Tagged ID of the member who left or was removed.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_chat_ids: optional array of string
Tagged IDs of chats among those resources.
haijun_project_ids: optional array of string
Tagged IDs of projects among those resources; the four ID lists hold at most the first 50 resources between them.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_ids: optional array of string
Tagged IDs of plugins among those resources.
skill_ids: optional array of string
Tagged IDs of tracks among those resources.
OrgUserTrustedDevicesRevoked object
An organization admin revoked a member's trusted devices and signed the member out of all active sessions.
type: optional "org_user_trusted_devices_revoked"
default: org_user_trusted_devices_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
completed: boolean
Whether the operation completed fully. False records an attempt that revoked the counted credentials but failed before finishing.
devices_revoked_count: number
Number of trusted devices revoked
sessions_revoked_count: number
Number of active sessions the member was signed out of
user_id: string
Tagged ID of the member whose trusted devices were revoked
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgUserViewed object
An organization user was viewed.
type: optional "org_user_viewed"
default: org_user_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
Tagged ID of the viewed user
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgUsersListed object
Organization users were listed.
type: optional "org_users_listed"
default: org_users_listed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrgWorkAcrossAppsDisabled object
The organization's "Let Haijun work across apps" setting was turned off.
type: optional "org_work_across_apps_disabled"
default: org_work_across_apps_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrgWorkAcrossAppsEnabled object
The organization's "Let Haijun work across apps" setting was turned on.
type: optional "org_work_across_apps_enabled"
default: org_work_across_apps_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_value: optional boolean or null
Setting value immediately after this change
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Setting value immediately before this change
OrganizationAddressUpdated object
The organization's billing or shipping address was updated.
type: optional "organization_address_updated"
default: organization_address_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
billing_address_updated: optional boolean or null
Whether the billing address was updated.
billing_name_updated: optional boolean or null
Whether the billing name was updated.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
shipping_address_updated: optional boolean or null
Whether the shipping address was updated.
shipping_name_updated: optional boolean or null
Whether the shipping name was updated.
OrganizationIconDeleted object
Organization's custom icon deleted.
type: optional "organization_icon_deleted"
default: organization_icon_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OrganizationIconUpdated object
Organization's custom icon uploaded or replaced.
type: optional "organization_icon_updated"
default: organization_icon_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunOrganizationSettingsUpdated object
Organization settings were updated.
type: optional "haijun_organization_settings_updated"
default: haijun_organization_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
updates: array of Name or Capabilities or RedactContent or 96 more
Name object
The organization name setting was changed.
type: optional "name"
default: name
current_value: optional string or null
Setting value immediately after this change
previous_value: optional string or null
Setting value immediately before this change
Capabilities object
The organization capabilities setting was changed.
type: optional "capabilities"
default: capabilities
current_value: optional array of string or null
Setting value immediately after this change
previous_value: optional array of string or null
Setting value immediately before this change
RedactContent object
The organization content-redaction setting was changed.
type: optional "redact_content"
default: redact_content
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
PublicProjectsEnabled object
The public projects setting was changed for the organization.
type: optional "public_projects_enabled"
default: public_projects_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
WebSearchEnabled object
The web search setting was changed.
type: optional "web_search_enabled"
default: web_search_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
GeolocationEnabled object
The geolocation setting was changed.
type: optional "geolocation_enabled"
default: geolocation_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
EnabledSaffron object
The memory setting was changed for the organization.
type: optional "enabled_saffron"
default: enabled_saffron
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
DataRetentionPeriods object
The data retention periods setting was changed for the organization.
type: optional "data_retention_periods"
default: data_retention_periods
current_value: optional array of object or null
Setting value immediately after this change
data_type: "all" or "artifact_private" or "artifact_shared" or 2 more
"all"
"artifact_private"
"artifact_shared"
"chat"
"project"
duration: number
minimum: -2147483648, maximum: 2147483647
timescale: "day" or "indefinite" or "month"
"day"
"indefinite"
"month"
previous_value: optional array of object or null
Setting value immediately before this change
data_type: "all" or "artifact_private" or "artifact_shared" or 2 more
"all"
"artifact_private"
"artifact_shared"
"chat"
"project"
duration: number
minimum: -2147483648, maximum: 2147483647
timescale: "day" or "indefinite" or "month"
"day"
"indefinite"
"month"
MembersLimit object
The members limit setting was changed for the organization.
type: optional "members_limit"
default: members_limit
current_value: optional number or null
Setting value immediately after this change
previous_value: optional number or null
Setting value immediately before this change
HaijunAPIInArtifactsEnabled object
The Haijun API in Artifacts setting was changed.
type: optional "haijun_api_in_artifacts_enabled"
default: haijun_api_in_artifacts_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
SupportContactMode object
The support contact routing mode setting was changed for the organization.
type: optional "support_contact_mode"
default: support_contact_mode
current_value: optional "ai_support_only" or "human_support_restricted" or "unspecified" or null
Setting value immediately after this change
"ai_support_only"
"human_support_restricted"
"unspecified"
previous_value: optional "ai_support_only" or "human_support_restricted" or "unspecified" or null
Setting value immediately before this change
"ai_support_only"
"human_support_restricted"
"unspecified"
SupportContactAlwaysIncludeAdminsOwners object
The support contact always-include-admins-owners setting was changed for the organization.
type: optional "support_contact_always_include_admins_owners"
default: support_contact_always_include_admins_owners
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
SupportContactDesignatedGroups object
The support contact designated groups setting was changed for the organization.
type: optional "support_contact_designated_groups"
default: support_contact_designated_groups
current_value: optional array of string or null
Setting value immediately after this change
previous_value: optional array of string or null
Setting value immediately before this change
SubscriptionItemQuotas object
The organization's subscription seat quotas were changed.
type: optional "subscription_item_quotas"
default: subscription_item_quotas
current_value: optional map[number] or null
Seat-type to quantity mapping immediately after this change. A null quantity means the item is unlimited/unmetered.
previous_value: optional map[number] or null
Seat-type to quantity mapping immediately before this change. A null quantity means the item was unlimited/unmetered.
MembersBulkSeatTierAssignment object
All organization members were assigned the specified seat tier.
type: optional "members_bulk_seat_tier_assignment"
default: members_bulk_seat_tier_assignment
current_value: optional string or null
The seat tier every member was assigned to
member_count: optional number or null
Number of members whose seat tier was changed
previous_value: optional string or null
Not populated; members may have held differing seat tiers before the bulk assignment
HaijunCodeWebEnabled object
The Haijun Code cloud sessions setting was changed for the organization.
type: optional "haijun_code_web_enabled"
default: haijun_code_web_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeDesktopBypassPermissionsEnabled object
The Haijun Code Desktop bypass-permissions mode setting was changed for the organization.
type: optional "haijun_code_desktop_bypass_permissions_enabled"
default: haijun_code_desktop_bypass_permissions_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeDesktopAutoPermissionsEnabled object
The Haijun Code Desktop auto-permissions mode setting was changed for the organization.
type: optional "haijun_code_desktop_auto_permissions_enabled"
default: haijun_code_desktop_auto_permissions_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
SkillsEnabled object
The Haijun.ai tracks setting was changed for the organization.
type: optional "skills_enabled"
default: skills_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
WorkbenchCompletionFeedbackEnabled object
The Workbench completion feedback setting was changed for the organization.
type: optional "workbench_completion_feedback_enabled"
default: workbench_completion_feedback_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAICompletionFeedbackEnabled object
The Haijun.ai completion feedback setting was changed for the organization.
type: optional "haijun_ai_completion_feedback_enabled"
default: haijun_ai_completion_feedback_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAIIntegrationSharingEnabled object
The Haijun.ai integration sharing setting was changed for the organization.
type: optional "haijun_ai_integration_sharing_enabled"
default: haijun_ai_integration_sharing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAIChatSharingEnabled object
The Haijun.ai chat sharing setting was changed for the organization.
type: optional "haijun_ai_chat_sharing_enabled"
default: haijun_ai_chat_sharing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAICcrSharingEnabled object
The Haijun.ai remote Haijun Code session sharing setting was changed for the organization.
type: optional "haijun_ai_ccr_sharing_enabled"
default: haijun_ai_ccr_sharing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAICcrSupportSharingEnabled object
The Juglow support access setting for Haijun Code sessions was changed for the organization.
type: optional "haijun_ai_ccr_support_sharing_enabled"
default: haijun_ai_ccr_support_sharing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
BatchesDownloadUiVisibility object
The batches download UI visibility setting was changed for the organization.
type: optional "batches_download_ui_visibility"
default: batches_download_ui_visibility
current_value: optional "all" or "none" or "selected" or "unspecified" or null
Setting value immediately after this change
"all"
"none"
"selected"
"unspecified"
previous_value: optional "all" or "none" or "selected" or "unspecified" or null
Setting value immediately before this change
"all"
"none"
"selected"
"unspecified"
AllowedInviteDomains object
The allowed invite domains setting was changed for the organization.
type: optional "allowed_invite_domains"
default: allowed_invite_domains
current_value: optional array of string or null
Setting value immediately after this change
previous_value: optional array of string or null
Setting value immediately before this change
WebSearchAPISettings object
The web search API setting was changed for the organization.
type: optional "web_search_api_settings"
default: web_search_api_settings
current_value: optional object or null
Setting value immediately after this change
domain_filters: object or null
Allowed/blocked domain filters shared by web_search and web_fetch tools.
allowed_domains: optional array of string or null
blocked_domains: optional array of string or null
is_enabled: boolean
previous_value: optional object or null
Setting value immediately before this change
domain_filters: object or null
Allowed/blocked domain filters shared by web_search and web_fetch tools.
allowed_domains: optional array of string or null
blocked_domains: optional array of string or null
is_enabled: boolean
WebFetchAPISettings object
The web fetch API setting was changed for the organization.
type: optional "web_fetch_api_settings"
default: web_fetch_api_settings
current_value: optional object or null
Setting value immediately after this change
domain_filters: object or null
Allowed/blocked domain filters shared by web_search and web_fetch tools.
allowed_domains: optional array of string or null
blocked_domains: optional array of string or null
is_enabled: boolean
previous_value: optional object or null
Setting value immediately before this change
domain_filters: object or null
Allowed/blocked domain filters shared by web_search and web_fetch tools.
allowed_domains: optional array of string or null
blocked_domains: optional array of string or null
is_enabled: boolean
DefaultWorkspaceSettings object
The default workspace setting was changed for the organization.
type: optional "default_workspace_settings"
default: default_workspace_settings
current_value: optional object or null
Setting value immediately after this change
enable_api_keys: optional boolean
default: true
previous_value: optional object or null
Setting value immediately before this change
enable_api_keys: optional boolean
default: true
BatchesDownloadUiEnabledWorkspaceIDs object
The batches download UI enabled workspace IDs setting was changed for the organization.
type: optional "batches_download_ui_enabled_workspace_ids"
default: batches_download_ui_enabled_workspace_ids
current_value: optional array of string or null
Setting value immediately after this change
previous_value: optional array of string or null
Setting value immediately before this change
HaijunCodeManagedSettings object
The organization's Haijun Code managed settings were changed.
The full previous and current settings content is provided in the previous_value and current_value fields.
type: optional "haijun_code_managed_settings"
default: haijun_code_managed_settings
current_value: optional map[unknown] or null
current_version: optional number or null
previous_value: optional map[unknown] or null
previous_version: optional number or null
settings_uuid: optional string or null
AccountSessionDurationSeconds object
Tracks changes to the enterprise account session duration setting (in seconds).
type: optional "account_session_duration_seconds"
default: account_session_duration_seconds
current_value: optional number or null
Setting value immediately after this change
previous_value: optional number or null
Setting value immediately before this change
VcsConnections object
Tracks changes to VCS (GitHub, etc.) organization connections.
type: optional "vcs_connections"
default: vcs_connections
current_value: optional array of object or null
Setting value immediately after this change
type: "github"
Supported Version Control System providers.
org_name: string
metadata: optional map[string] or null
org_id: optional string or null
previous_value: optional array of object or null
Setting value immediately before this change
type: "github"
Supported Version Control System providers.
org_name: string
metadata: optional map[string] or null
org_id: optional string or null
DisabledAdminRequestTypes object
Tracks changes to which admin request types are disabled.
type: optional "disabled_admin_request_types"
default: disabled_admin_request_types
current_value: optional array of string or null
Setting value immediately after this change
previous_value: optional array of string or null
Setting value immediately before this change
MemberUsageDashboardVisible object
The member usage dashboard visibility setting was changed for the organization.
type: optional "member_usage_dashboard_visible"
default: member_usage_dashboard_visible
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
CodeExecutionNetworkEgressEnabled object
The code execution network egress setting was changed for the organization.
type: optional "code_execution_network_egress_enabled"
default: code_execution_network_egress_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
CodeExecutionDomainAllowlistChanged object
The code execution domain allowlist setting was changed for the organization.
type: optional "code_execution_domain_allowlist_changed"
default: code_execution_domain_allowlist_changed
current_value: optional array of string or null
Setting value immediately after this change
previous_value: optional array of string or null
Setting value immediately before this change
CodeExecutionDomainAllowlistTemplateChanged object
The code execution domain allowlist template setting was changed for the organization.
type: optional "code_execution_domain_allowlist_template_changed"
default: code_execution_domain_allowlist_template_changed
current_value: optional "custom" or "full_egress" or "package_managers" or "unspecified" or null
Setting value immediately after this change
"custom"
"full_egress"
"package_managers"
"unspecified"
previous_value: optional "custom" or "full_egress" or "package_managers" or "unspecified" or null
Setting value immediately before this change
"custom"
"full_egress"
"package_managers"
"unspecified"
ChatEnabled object
The chat setting was changed for the organization.
type: optional "chat_enabled"
default: chat_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeQuickWebSetupEnabled object
The Haijun Code quick web setup setting was changed for the organization.
type: optional "haijun_code_quick_web_setup_enabled"
default: haijun_code_quick_web_setup_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeTeamMemoryMode object
The Haijun Code team memory mode setting was changed for the organization.
type: optional "haijun_code_team_memory_mode"
default: haijun_code_team_memory_mode
current_value: optional "all_org_members" or "github_repo" or "off" or 2 more or null
Setting value immediately after this change
"all_org_members"
"github_repo"
"off"
"specific_groups"
"unspecified"
previous_value: optional "all_org_members" or "github_repo" or "off" or 2 more or null
Setting value immediately before this change
"all_org_members"
"github_repo"
"off"
"specific_groups"
"unspecified"
BrowserExtensionSettings object
The browser extension setting was changed for the organization.
type: optional "browser_extension_settings"
default: browser_extension_settings
current_value: optional map[unknown] or null
Setting value immediately after this change
previous_value: optional map[unknown] or null
Setting value immediately before this change
IsDesktopExtensionAllowlistEnabled object
The desktop extension allowlist setting was changed for the organization.
type: optional "is_desktop_extension_allowlist_enabled"
default: is_desktop_extension_allowlist_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
AllowMemberDataExport object
The per-member self-serve data export setting was changed for the organization.
type: optional "allow_member_data_export"
default: allow_member_data_export
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAIDesignEnabled object
The Haijun Design setting was changed for the organization.
type: optional "haijun_ai_design_enabled"
default: haijun_ai_design_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceEnabled object
The setting that turns Haijun Science on or off for the organization was changed.
type: optional "haijun_science_enabled"
default: haijun_science_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceMemoryEnabled object
The Haijun Science memory setting was changed for the organization.
type: optional "haijun_science_memory_enabled"
default: haijun_science_memory_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceCustomConnectorsEnabled object
The Haijun Science custom connectors setting was changed for the organization.
type: optional "haijun_science_custom_connectors_enabled"
default: haijun_science_custom_connectors_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceCustomSkillsEnabled object
The Haijun Science custom tracks setting was changed for the organization.
type: optional "haijun_science_custom_skills_enabled"
default: haijun_science_custom_skills_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceManagedNetworkAllowlistEnabled object
The Haijun Science setting that puts the network allowlist under the organization's management, instead of each member managing their own, was changed for the organization.
type: optional "haijun_science_managed_network_allowlist_enabled"
default: haijun_science_managed_network_allowlist_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceSSHHostsEnabled object
The Haijun Science SSH hosts setting was changed for the organization.
type: optional "haijun_science_ssh_hosts_enabled"
default: haijun_science_ssh_hosts_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceModalEnabled object
The Haijun Science setting that lets members connect Modal cloud compute was changed for the organization.
type: optional "haijun_science_modal_enabled"
default: haijun_science_modal_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceScientificModelEndpointsEnabled object
The Haijun Science scientific model endpoints setting was changed for the organization.
type: optional "haijun_science_scientific_model_endpoints_enabled"
default: haijun_science_scientific_model_endpoints_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceNetworkAllowlistChanged object
The hostnames on the organization's Haijun Science network allowlist, which applies to members while the organization manages the allowlist, were changed.
type: optional "haijun_science_network_allowlist_changed"
default: haijun_science_network_allowlist_changed
current_value: optional array of string or null
Setting value immediately after this change: the organization's complete saved allowlist (built-in and custom domains alike) as lowercase hostnames, each optionally prefixed with '*.'. Null means no list is saved (this change reset it), so Haijun Science's built-in allowlist applies; an empty list means a list with no domains on it is saved.
previous_value: optional array of string or null
Setting value immediately before this change: the organization's complete saved allowlist (built-in and custom domains alike) as lowercase hostnames, each optionally prefixed with '*.'. Null means no list was saved at that point (never saved, or since reset), so Haijun Science's built-in allowlist applied; an empty list means a list with no domains on it had been saved.
HaijunScienceModalWorkspaceAllowlistChanged object
The Haijun Science Modal cloud compute workspace allowlist setting was changed for the organization.
type: optional "haijun_science_modal_workspace_allowlist_changed"
default: haijun_science_modal_workspace_allowlist_changed
current_value: optional array of string or null
Setting value immediately after this change: the Modal workspace names members can connect to. Null or an empty list means any workspace is allowed.
previous_value: optional array of string or null
Setting value immediately before this change: the Modal workspace names members could connect to. Null or an empty list means any workspace was allowed.
HaijunSciencePackageMirrorCondaChannelChanged object
The Haijun Science package mirror setting for the conda channel was changed for the organization.
type: optional "haijun_science_package_mirror_conda_channel_changed"
default: haijun_science_package_mirror_conda_channel_changed
current_value: optional string or null
Setting value immediately after this change: the HTTPS URL of the organization's conda channel mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none is set.
previous_value: optional string or null
Setting value immediately before this change: the HTTPS URL of the organization's conda channel mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none was set.
HaijunSciencePackageMirrorPipIndexChanged object
The Haijun Science package mirror setting for the Python package index was changed for the organization.
type: optional "haijun_science_package_mirror_pip_index_changed"
default: haijun_science_package_mirror_pip_index_changed
current_value: optional string or null
Setting value immediately after this change: the HTTPS URL of the organization's Python (pip) package index mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none is set.
previous_value: optional string or null
Setting value immediately before this change: the HTTPS URL of the organization's Python (pip) package index mirror, as saved (scheme, host, any non-default port, and path; the setting does not accept a username or password, a query string or a fragment in the URL). Null means none was set.
HaijunAISkillPluginsScanningEnabled object
The track and plugin security scanning setting was changed for the organization.
type: optional "haijun_ai_skill_plugins_scanning_enabled"
default: haijun_ai_skill_plugins_scanning_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
ArtifactPublishingEnabled object
The Artifact publishing setting was changed for the organization.
type: optional "artifact_publishing_enabled"
default: artifact_publishing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
ArtifactExternalSharingEnabled object
The Artifact external sharing setting was changed for the organization.
type: optional "artifact_external_sharing_enabled"
default: artifact_external_sharing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
ArtifactPresenceEnabled object
The Artifact presence setting was changed for the organization.
type: optional "artifact_presence_enabled"
default: artifact_presence_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAISkillSharingEnabled object
The Haijun.ai track sharing setting was changed for the organization.
type: optional "haijun_ai_skill_sharing_enabled"
default: haijun_ai_skill_sharing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAISkillSharingOrgEnabled object
The Haijun.ai organization-wide track sharing setting was changed for the organization.
type: optional "haijun_ai_skill_sharing_org_enabled"
default: haijun_ai_skill_sharing_org_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAISkillSharingGroupEnabled object
The Haijun.ai group-based track sharing setting was changed for the organization.
type: optional "haijun_ai_skill_sharing_group_enabled"
default: haijun_ai_skill_sharing_group_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAISkillPublishPolicy object
The Haijun.ai organization track publish policy was changed for the organization.
type: optional "haijun_ai_skill_publish_policy"
default: haijun_ai_skill_publish_policy
current_value: optional "off" or "open" or "review" or "unspecified" or null
Setting value immediately after this change
"off"
"open"
"review"
"unspecified"
previous_value: optional "off" or "open" or "review" or "unspecified" or null
Setting value immediately before this change
"off"
"open"
"review"
"unspecified"
HaijunCodeRemoteControlEnabled object
The Haijun Code remote control setting was changed for the organization.
type: optional "haijun_code_remote_control_enabled"
default: haijun_code_remote_control_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeRemoteControlDefaultEnabled object
The Haijun Code remote control auto-enable default was changed for the organization.
type: optional "haijun_code_remote_control_default_enabled"
default: haijun_code_remote_control_default_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeRoutinesEnabled object
The Haijun Code routines setting was changed for the organization.
type: optional "haijun_code_routines_enabled"
default: haijun_code_routines_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeWorkflowsEnabled object
The Haijun Code Workflows setting was changed for the organization.
type: optional "haijun_code_workflows_enabled"
default: haijun_code_workflows_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
FrontierServicesDataUseEnabled object
The frontier services data use setting was changed for the organization.
type: optional "frontier_services_data_use_enabled"
default: frontier_services_data_use_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
LtiCourseProjectsEnabled object
The LTI course projects setting was changed for the organization.
type: optional "lti_course_projects_enabled"
default: lti_course_projects_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAISkillCreationEnabled object
The Haijun.ai track creation setting was changed for the organization.
type: optional "haijun_ai_skill_creation_enabled"
default: haijun_ai_skill_creation_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeGitHubAnalyticsEnabled object
The Haijun Code GitHub analytics setting was changed for the organization.
type: optional "haijun_code_github_analytics_enabled"
default: haijun_code_github_analytics_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeHideManagedEnvironments object
The Haijun Code hide managed environments setting was changed for the organization.
type: optional "haijun_code_hide_managed_environments"
default: haijun_code_hide_managed_environments
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeAllowSessionPoolMoves object
The Haijun Code allow session pool moves setting was changed for the organization.
type: optional "haijun_code_allow_session_pool_moves"
default: haijun_code_allow_session_pool_moves
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeDisableJuglowCompute object
The Haijun Code disable Juglow compute setting was changed for the organization.
type: optional "haijun_code_disable_juglow_compute"
default: haijun_code_disable_juglow_compute
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeMetricsLoggingEnabled object
The Haijun Code metrics logging setting was changed for the organization.
type: optional "haijun_code_metrics_logging_enabled"
default: haijun_code_metrics_logging_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeFastModeEnabled object
The Haijun Code fast mode setting was changed for the organization.
type: optional "haijun_code_fast_mode_enabled"
default: haijun_code_fast_mode_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunCodeTrustedDevicesRequired object
The Haijun Code trusted devices setting was changed for the organization.
type: optional "haijun_code_trusted_devices_required"
default: haijun_code_trusted_devices_required
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
CoworkTrustedDevicesRequired object
The Cowork trusted devices enforcement setting was changed for the organization.
type: optional "cowork_trusted_devices_required"
default: cowork_trusted_devices_required
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
InlineVisualizationsEnabled object
The inline visualizations setting was changed for the organization.
type: optional "inline_visualizations_enabled"
default: inline_visualizations_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
OrganizationBannerSettings object
The organization banner setting was changed.
type: optional "organization_banner_settings"
default: organization_banner_settings
current_value: optional map[unknown] or null
Setting value immediately after this change
previous_value: optional map[unknown] or null
Setting value immediately before this change
HaijunInSlackSettings object
The Haijun in Slack setting was changed for the organization.
type: optional "haijun_in_slack_settings"
default: haijun_in_slack_settings
current_value: optional map[unknown] or null
Setting value immediately after this change
previous_value: optional map[unknown] or null
Setting value immediately before this change
HaijunCodeDefaultWorkerEnvironmentID object
The Haijun Code default worker environment setting was changed for the organization.
type: optional "haijun_code_default_worker_environment_id"
default: haijun_code_default_worker_environment_id
current_value: optional string or null
Setting value immediately after this change
previous_value: optional string or null
Setting value immediately before this change
HaijunCodeDefaultWorkerPoolID object
The Haijun Code default worker pool setting was changed for the organization.
type: optional "haijun_code_default_worker_pool_id"
default: haijun_code_default_worker_pool_id
current_value: optional string or null
Setting value immediately after this change
previous_value: optional string or null
Setting value immediately before this change
ManagedAgentsEnabled object
The managed agents setting was changed for the organization.
type: optional "managed_agents_enabled"
default: managed_agents_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunScienceFeaturedConnectorsDefaultChanged object
The organization-wide default for Haijun Science featured connectors was changed for the organization.
type: optional "haijun_science_featured_connectors_default_changed"
default: haijun_science_featured_connectors_default_changed
current_value: optional boolean or null
Setting value immediately after this change: whether featured connectors not set individually are on for members. Null means no organization-wide default is set (this change removed it), so the plan default applies.
previous_value: optional boolean or null
Setting value immediately before this change: whether featured connectors not set individually were on for members. Null means no organization-wide default was set, so the plan default applied.
HaijunScienceFeaturedConnectorsEnabledListChanged object
The list of Haijun Science featured connectors individually turned on for members was changed for the organization.
type: optional "haijun_science_featured_connectors_enabled_list_changed"
default: haijun_science_featured_connectors_enabled_list_changed
current_value: optional array of string or null
Setting value immediately after this change: the ids of the featured connectors individually turned on. Null or an empty list means none.
previous_value: optional array of string or null
Setting value immediately before this change: the ids of the featured connectors individually turned on. Null or an empty list means none.
HaijunScienceFeaturedConnectorsDisabledListChanged object
The list of Haijun Science featured connectors individually turned off for members was changed for the organization.
type: optional "haijun_science_featured_connectors_disabled_list_changed"
default: haijun_science_featured_connectors_disabled_list_changed
current_value: optional array of string or null
Setting value immediately after this change: the ids of the featured connectors individually turned off. Null or an empty list means none.
previous_value: optional array of string or null
Setting value immediately before this change: the ids of the featured connectors individually turned off. Null or an empty list means none.
HaijunScienceFeaturedSkillsDefaultChanged object
The organization-wide default for Haijun Science featured tracks was changed for the organization.
type: optional "haijun_science_featured_skills_default_changed"
default: haijun_science_featured_skills_default_changed
current_value: optional boolean or null
Setting value immediately after this change: whether featured tracks not set individually are on for members. Null means no organization-wide default is set (this change removed it), so the plan default applies.
previous_value: optional boolean or null
Setting value immediately before this change: whether featured tracks not set individually were on for members. Null means no organization-wide default was set, so the plan default applied.
HaijunScienceFeaturedSkillsEnabledListChanged object
The list of Haijun Science featured tracks individually turned on for members was changed for the organization.
type: optional "haijun_science_featured_skills_enabled_list_changed"
default: haijun_science_featured_skills_enabled_list_changed
current_value: optional array of string or null
Setting value immediately after this change: the ids of the featured tracks individually turned on. Null or an empty list means none.
previous_value: optional array of string or null
Setting value immediately before this change: the ids of the featured tracks individually turned on. Null or an empty list means none.
HaijunScienceFeaturedSkillsDisabledListChanged object
The list of Haijun Science featured tracks individually turned off for members was changed for the organization.
type: optional "haijun_science_featured_skills_disabled_list_changed"
default: haijun_science_featured_skills_disabled_list_changed
current_value: optional array of string or null
Setting value immediately after this change: the ids of the featured tracks individually turned off. Null or an empty list means none.
previous_value: optional array of string or null
Setting value immediately before this change: the ids of the featured tracks individually turned off. Null or an empty list means none.
FilesAPIEnabled object
The Files API was turned on or off for the organization.
type: optional "files_api_enabled"
default: files_api_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
SkillsAPIEnabled object
The Tracks API was turned on or off for the organization.
type: optional "skills_api_enabled"
default: skills_api_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
PasswordManagerIntegrationEnabled object
The password manager integration setting was changed for the organization.
type: optional "password_manager_integration_enabled"
default: password_manager_integration_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
APIKeyCreationEnabled object
The setting that allows members to create new API keys was changed for the organization.
type: optional "api_key_creation_enabled"
default: api_key_creation_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAcademyInferenceEnabled object
The setting that lets members use Haijun in Haijun Academy was changed for the organization.
type: optional "haijun_academy_inference_enabled"
default: haijun_academy_inference_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAIProjectSharingEnabled object
The Haijun.ai project sharing setting (whether members can share projects with new recipients: people, groups, or the whole organization) was changed for the organization.
type: optional "haijun_ai_project_sharing_enabled"
default: haijun_ai_project_sharing_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
OwnedProjectsAccessRestored object
Access to owned projects was restored.
type: optional "owned_projects_access_restored"
default: owned_projects_access_restored
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
user_id: optional string or null
Tagged ID of the member whose access to their owned projects was restored, when known.
PaymentMethodUpdated object
The organization's default payment method was updated.
type: optional "payment_method_updated"
default: payment_method_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PendingShareCreated object
A pending share of a project or track was created for an email address that is not yet an organization member.
type: optional "pending_share_created"
default: pending_share_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
invitee_email: string
Email address the share was created for.
resource_id: string
Tagged ID of the resource being shared.
resource_type: string
The type of resource being shared.
role: string
The role that will be granted when the invitee joins the organization.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PendingShareRevoked object
A pending share of a project or track was revoked before the invitee joined the organization.
type: optional "pending_share_revoked"
default: pending_share_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
invitee_email: string
Email address the share had been created for.
resource_id: string
Tagged ID of the resource that was shared.
resource_type: string
The type of resource that was shared.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PhoneCodeSent object
User requested a phone verification code.
type: optional "phone_code_sent"
default: phone_code_sent
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PhoneCodeVerified object
User successfully verified their phone code.
type: optional "phone_code_verified"
default: phone_code_verified
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformAgentArchived object
An agent was archived on the API platform.
type: optional "platform_agent_archived"
default: platform_agent_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was archived, e.g. "agent_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentCreated object
An agent was created on the API platform.
type: optional "platform_agent_created"
default: platform_agent_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was created, e.g. "agent_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeleted object
An agent was deleted from the API platform.
type: optional "platform_agent_deleted"
default: platform_agent_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was deleted, e.g. "agent_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeploymentArchived object
An agent deployment was archived on the API platform.
type: optional "platform_agent_deployment_archived"
default: platform_agent_deployment_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deployment_id: string
The agent deployment that was archived, e.g. "depl_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeploymentCreated object
An agent deployment was created on the API platform.
type: optional "platform_agent_deployment_created"
default: platform_agent_deployment_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deployment_id: string
The agent deployment that was created, e.g. "depl_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeploymentDeleted object
An agent deployment was deleted from the API platform.
type: optional "platform_agent_deployment_deleted"
default: platform_agent_deployment_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deployment_id: string
The agent deployment that was deleted, e.g. "depl_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeploymentPaused object
An agent deployment was paused on the API platform.
type: optional "platform_agent_deployment_paused"
default: platform_agent_deployment_paused
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deployment_id: string
The agent deployment that was paused, e.g. "depl_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeploymentRunTriggered object
An agent deployment was run on demand on the API platform.
type: optional "platform_agent_deployment_run_triggered"
default: platform_agent_deployment_run_triggered
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deployment_id: string
The agent deployment that was run, e.g. "depl_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeploymentUnpaused object
An agent deployment was resumed on the API platform.
type: optional "platform_agent_deployment_unpaused"
default: platform_agent_deployment_unpaused
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deployment_id: string
The agent deployment that was resumed, e.g. "depl_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentDeploymentUpdated object
An agent deployment was updated on the API platform.
type: optional "platform_agent_deployment_updated"
default: platform_agent_deployment_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
deployment_id: string
The agent deployment that was updated, e.g. "depl_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionArchived object
An agent session was archived on the API platform.
type: optional "platform_agent_session_archived"
default: platform_agent_session_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The agent session that was archived, e.g. "session_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionCreated object
An agent session was created on the API platform.
type: optional "platform_agent_session_created"
default: platform_agent_session_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The agent session that was created, e.g. "session_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionDeleted object
An agent session was deleted from the API platform.
type: optional "platform_agent_session_deleted"
default: platform_agent_session_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The agent session that was deleted, e.g. "session_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionResourceAdded object
A resource was attached to an agent session.
type: optional "platform_agent_session_resource_added"
default: platform_agent_session_resource_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resource_id: string
The resource that was attached, e.g. "resource_01HX...".
session_id: string
The agent session the resource was attached to, e.g. "session_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionResourceDeleted object
A resource attached to an agent session was removed.
type: optional "platform_agent_session_resource_deleted"
default: platform_agent_session_resource_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resource_id: string
The resource that was removed, e.g. "resource_01HX...".
session_id: string
The agent session the resource belonged to, e.g. "session_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionResourceUpdated object
A resource attached to an agent session was updated.
type: optional "platform_agent_session_resource_updated"
default: platform_agent_session_resource_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resource_id: string
The resource that was updated, e.g. "resource_01HX...".
session_id: string
The agent session the resource belongs to, e.g. "session_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionThreadArchived object
A thread within an agent session was archived.
type: optional "platform_agent_session_thread_archived"
default: platform_agent_session_thread_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The agent session the thread belongs to, e.g. "session_01HX...".
thread_id: string
The thread that was archived, e.g. "thread_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentSessionUpdated object
An agent session was updated on the API platform.
type: optional "platform_agent_session_updated"
default: platform_agent_session_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
session_id: string
The agent session that was updated, e.g. "session_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAgentUpdated object
An agent was updated on the API platform.
type: optional "platform_agent_updated"
default: platform_agent_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
agent_id: string
The agent that was updated, e.g. "agent_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged workspace ID, e.g. "wrkspc_01HX...". Optional because org-scoped credentials may not resolve a workspace at request time.
PlatformAPIKeyCreated object
An API key was created.
type: optional "platform_api_key_created"
default: platform_api_key_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
api_key_id: string
Tagged ID of the created API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
principal_id: optional string or null
For an identity-linked API key, the tagged ID of the user (e.g. "user_01HX...") or service account (e.g. "svac_01HX...") the key acts as. Absent for keys not linked to an identity.
principal_type: optional "service_account" or "unspecified" or "user" or null
For an identity-linked API key, the kind of identity the key acts as: "user" or "service_account". Absent for keys not linked to an identity.
"service_account"
"unspecified"
"user"
scope: optional Organization or Workspace or null
Where the API key belongs: one workspace ({"type": "workspace", "workspace_id": "wrkspc_..."}, with the workspace's ID even when it is the organization's default workspace), or the whole organization ({"type": "organization"}) for an identity-linked API key that has no workspace. May be absent on activities recorded before this field was introduced.
Organization object
The API key belongs to the whole organization and has no workspace.
type: optional "organization"
default: organization
Workspace object
The API key belongs to one workspace.
type: optional "workspace"
default: workspace
workspace_id: string
Tagged ID of the workspace the API key belongs to, including when that is the organization's default workspace.
PlatformAPIKeyUpdated object
An API key was updated.
type: optional "platform_api_key_updated"
default: platform_api_key_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
api_key_id: string
Tagged ID of the updated API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "name" or "status" or "unspecified" or "workspace"
The API key field that changed
"name"
"status"
"unspecified"
"workspace"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
PlatformAppAttestAuthentication object
An attested mobile device attempted to exchange an Apple App Attest assertion for Juglow API credentials.
type: optional "platform_app_attest_authentication"
default: platform_app_attest_authentication
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
event_data: optional object or null
Details of the authentication attempt.
external_client_id: optional string or null
The registered external client the device presented, e.g. "clid_01HXZ4J2N8K5P7R9T3V6W1Y4M0".
kid_hash: optional string or null
A truncated hash of the device's attested key identifier.
workspace_id: optional string or null
The tagged ID of the workspace the minted token is bound to.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
request_id: optional string or null
The Juglow API request identifier for correlation.
status: optional object or null
The outcome of the token exchange.
outcome: string
Whether the token exchange succeeded or was denied.
reason: optional string or null
A short reason code when the exchange did not succeed.
PlatformBillingUpgradedToPrepaid object
The organization's API billing was upgraded to the prepaid plan.
type: optional "platform_billing_upgraded_to_prepaid"
default: platform_billing_upgraded_to_prepaid
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
previous_billing_type: string
The organization's billing type before this upgrade, for example "api_evaluation".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformClearanceWorkspaceProgramRequestCleared object
A workspace's clearance program assignment was removed.
type: optional "platform_clearance_workspace_program_request_cleared"
default: platform_clearance_workspace_program_request_cleared
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
program_slug: string
The clearance program's identifier
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformClearanceWorkspaceProgramRequestSet object
A workspace's clearance program assignment was created or updated.
type: optional "platform_clearance_workspace_program_request_set"
default: platform_clearance_workspace_program_request_set
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
opt_decision: "opt_in" or "opt_out" or "unspecified"
Whether the workspace is opted in or out of the program
"opt_in"
"opt_out"
"unspecified"
program_slug: string
The clearance program's identifier
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformCostReportViewed object
The cost report was viewed.
type: optional "platform_cost_report_viewed"
default: platform_cost_report_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformDreamArchived object
A Dream (asynchronous memory-consolidation job) was archived.
type: optional "platform_dream_archived"
default: platform_dream_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
dream_id: string
Tagged dream ID, e.g. "drm_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the dream belongs to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace.
PlatformDreamCancelled object
A Dream (asynchronous memory-consolidation job) was cancelled before it completed.
type: optional "platform_dream_cancelled"
default: platform_dream_cancelled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
dream_id: string
Tagged dream ID, e.g. "drm_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the dream belongs to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace.
PlatformDreamCreated object
A Dream (asynchronous memory-consolidation job) was created.
type: optional "platform_dream_created"
default: platform_dream_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
dream_id: string
Tagged dream ID, e.g. "drm_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the dream belongs to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace.
PlatformFederatedAuthentication object
A federated workload identity attempted to exchange an OIDC token for Juglow API credentials.
type: optional "platform_federated_authentication"
default: platform_federated_authentication
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
event_data: optional object or null
Details of the authentication attempt.
federation_rule_id: optional string or null
The federation rule that matched the request, e.g. "fdrl_01HXZ4J2N8K5P7R9T3V6W1Y4M0".
issuer_id: optional string or null
The registered identity issuer for the request, e.g. "fdis_01HXZ4H5M3K8P1R7T9V2W6Y4N0".
oidc_token: optional object or null
Details of the presented OIDC token.
claims: optional map[unknown] or null
The verified claims from the presented OIDC token.
jti: optional string or null
The presented token's unique identifier (its jti claim).
requested_service_account_id: optional string or null
The service account the caller requested to authenticate as, e.g. "svac_01HXZ4...".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
request_id: optional string or null
The Juglow API request identifier for correlation, e.g. "req_01HXZ4K7M9P2QR5T8V6W3Y1N0B".
resources: optional array of object
The resources involved in the exchange.
type: string
The kind of resource involved in the exchange.
id: string
The identifier of the resource involved in the exchange.
status: optional object or null
The outcome of the token exchange.
outcome: string
Whether the token exchange succeeded or was denied.
detail: optional string or null
A human-readable explanation when the exchange did not succeed. May contain values copied verbatim from the presented token's header (e.g. kid, alg) and error text; treat as caller-supplied free text.
reason: optional string or null
A short reason code when the exchange did not succeed.
PlatformFederationIssuerArchived object
An OIDC federation issuer was archived.
type: optional "platform_federation_issuer_archived"
default: platform_federation_issuer_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
federation_issuer_id: string
Tagged ID of the archived issuer
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformFederationIssuerCreated object
An OIDC federation issuer was created, registering an external identity provider that federation rules can trust for workload authentication.
type: optional "platform_federation_issuer_created"
default: platform_federation_issuer_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
federation_issuer_id: string
Tagged ID of the created issuer, e.g. "fdis_..."
issuer_url: string
URL of the external OIDC identity provider that was registered
jwks_source: string
How the issuer's token-signing keys are obtained — typically "discovery" (the issuer's OIDC discovery document), "explicit_url" (a fixed JWKS URL), or "inline" (keys supplied directly at registration). An unrecognized source is recorded verbatim.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
discovery_base: optional string or null
Base URL for the OIDC discovery document, if a custom base was registered. Only present when jwks_source is "discovery".
jwks_url: optional string or null
The fixed URL where the issuer publishes its token-signing keys. Only present when jwks_source is "explicit_url".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformFederationIssuerUpdated object
An OIDC federation issuer was updated.
type: optional "platform_federation_issuer_updated"
default: platform_federation_issuer_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
federation_issuer_id: string
Tagged ID of the updated issuer
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "ca_cert_pem_sha256" or "check_jti" or "discovery_base" or 8 more
The OIDC federation issuer field that changed
"ca_cert_pem_sha256"
"check_jti"
"discovery_base"
"issuer_url"
"jwks_keys_sha256"
"jwks_polling_disabled_at"
"jwks_source"
"jwks_url"
"max_jwt_lifetime_seconds"
"name"
"unspecified"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
PlatformFederationRuleArchived object
An OIDC federation rule was archived.
type: optional "platform_federation_rule_archived"
default: platform_federation_rule_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
federation_rule_id: string
Tagged ID of the archived rule
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformFederationRuleCreated object
An OIDC federation rule was created, allowing tokens from a federation issuer to authenticate as a service account or user. Rules may additionally match on token claims or a condition expression, which are not included in this event.
type: optional "platform_federation_rule_created"
default: platform_federation_rule_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
applies_to_all_workspaces: boolean
Whether the rule applies to all workspaces in the organization.
federation_issuer_id: string
Tagged ID of the federation issuer the rule trusts
federation_rule_id: string
Tagged ID of the created rule, e.g. "fdrl_..."
oauth_scope: string
Space-separated OAuth scopes that tokens minted through the rule carry, e.g. "workspace:inference" or "org:admin".
target_type: string
What the rule authenticates as — typically "service_account" or "user". An unrecognized kind is recorded verbatim.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
match_audience: optional string or null
Token audience the rule matches, if one was set.
match_subject_prefix: optional string or null
Matcher for the token's sub claim, if one was set: exact match unless the value ends with , which makes it a prefix match. An empty value matches any subject. Example: "repo:acme/".
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
target_id: optional string or null
Tagged ID of the service account the rule authenticates as, e.g. "svac_...". Absent when target_type is "user": user rules identify the target by token-claim lookup rather than a fixed ID.
target_lookup_attr: optional string or null
Name of the rule attribute whose value resolves the target user. Only present when target_type is "user".
workspace_id: optional string or null
Tagged ID of the workspace the rule references, if one was set. May be set alongside applies_to_all_workspaces, which takes precedence: the rule then covers every workspace in the organization.
PlatformFederationRuleUpdated object
An OIDC federation rule was updated.
type: optional "platform_federation_rule_updated"
default: platform_federation_rule_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
federation_rule_id: string
Tagged ID of the updated rule
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "applies_to_all_workspaces" or "attributes" or "description" or 12 more
The OIDC federation rule field that changed
"applies_to_all_workspaces"
"attributes"
"description"
"match_audience"
"match_claims"
"match_condition"
"match_subject_prefix"
"name"
"oauth_scope"
"target_id"
"target_lookup_attr"
"target_type"
"token_lifetime_seconds"
"unspecified"
"workspace_id"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
PlatformFederationRuleWorkspaceAdded object
A federation rule was enabled for a workspace.
type: optional "platform_federation_rule_workspace_added"
default: platform_federation_rule_workspace_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
federation_rule_id: string
Tagged ID of the federation rule
workspace_id: string
Tagged ID of the workspace the rule was enabled for
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformFederationRuleWorkspaceRemoved object
A federation rule was disabled for a workspace.
type: optional "platform_federation_rule_workspace_removed"
default: platform_federation_rule_workspace_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
federation_rule_id: string
Tagged ID of the federation rule
workspace_id: string
Tagged ID of the workspace the rule was disabled for
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformFileContentDownloaded object
Activity logged when file content is downloaded via GET /v1/files/{file_id}/content.
type: optional "platform_file_content_downloaded"
default: platform_file_content_downloaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
file_id: string
The tagged ID of the downloaded file
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformFileDeleted object
Activity logged when a file is deleted via DELETE /v1/files/{file_id}.
type: optional "platform_file_deleted"
default: platform_file_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
file_id: string
The tagged ID of the deleted file
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformFileUploaded object
Activity logged when a file is uploaded via POST /v1/files.
type: optional "platform_file_uploaded"
default: platform_file_uploaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
file_id: string
The tagged ID of the uploaded file
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
session_id: optional string or null
The tagged session ID (agent-api only)
PlatformMemoryCreated object
An agent memory document was created.
type: optional "platform_memory_created"
default: platform_memory_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_id: string
Tagged memory ID, e.g. "mem_01HX...".
memory_store_id: string
Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
memory_version_id: optional string or null
Tagged ID of the memory version produced by this change, e.g. "memver_01HX...". Links this event to the version history.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformMemoryDeleted object
An agent memory document was deleted.
type: optional "platform_memory_deleted"
default: platform_memory_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_id: string
Tagged memory ID, e.g. "mem_01HX...".
memory_store_id: string
Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
memory_version_id: optional string or null
Tagged ID of the memory version produced by this change — the deletion tombstone, e.g. "memver_01HX...". Links this event to the version history.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformMemoryStoreArchived object
An agent memory store was archived. Archived stores reject new memory writes and cannot be attached to new sessions; deletion and redaction remain permitted for privacy scrubbing.
type: optional "platform_memory_store_archived"
default: platform_memory_store_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_store_id: string
Tagged memory store ID, e.g. "memstore_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformMemoryStoreCreated object
An agent memory store was created.
type: optional "platform_memory_store_created"
default: platform_memory_store_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_store_id: string
Tagged memory store ID, e.g. "memstore_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformMemoryStoreDeleted object
An agent memory store was deleted. Memory content removal may complete asynchronously for very large stores.
type: optional "platform_memory_store_deleted"
default: platform_memory_store_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_store_id: string
Tagged memory store ID, e.g. "memstore_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformMemoryStoreUpdated object
An agent memory store's name, description, or metadata was updated.
type: optional "platform_memory_store_updated"
default: platform_memory_store_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_store_id: string
Tagged memory store ID, e.g. "memstore_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformMemoryUpdated object
An agent memory document's content or path was updated.
type: optional "platform_memory_updated"
default: platform_memory_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_id: string
Tagged memory ID, e.g. "mem_01HX...".
memory_store_id: string
Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
memory_version_id: optional string or null
Tagged ID of the memory version produced by this change, e.g. "memver_01HX...". Links this event to the version history.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformMemoryVersionRedacted object
A historical version of an agent memory document was redacted. Redaction scrubs the stored content of a specific version while preserving the version's existence in the history.
type: optional "platform_memory_version_redacted"
default: platform_memory_version_redacted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
memory_id: string
Tagged ID of the memory the version belongs to, e.g. "mem_01HX...".
memory_store_id: string
Tagged ID of the memory store the memory belongs to, e.g. "memstore_01HX...".
memory_version_id: string
Tagged memory version ID, e.g. "memver_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace the request was scoped to, e.g. "wrkspc_01HX...". For organization-scoped credentials this is the organization's default workspace. May differ from the workspace the store was created in when the store is account-scoped.
PlatformOAuthAppCreated object
An OAuth app was created.
type: optional "platform_oauth_app_created"
default: platform_oauth_app_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
oauth_app_id: string
Tagged ID of the created app
workspace_id: string
Tagged ID of the workspace the app is scoped to
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformOAuthAppRevoked object
An OAuth app was revoked.
type: optional "platform_oauth_app_revoked"
default: platform_oauth_app_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
oauth_app_id: string
Tagged ID of the revoked app
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformOAuthAppUpdated object
An OAuth app was updated.
type: optional "platform_oauth_app_updated"
default: platform_oauth_app_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
oauth_app_id: string
Tagged ID of the updated app
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "apple_ios_attestation_environment" or "apple_ios_bundles" or "name" or 2 more
The OAuth app field that changed
"apple_ios_attestation_environment"
"apple_ios_bundles"
"name"
"status"
"unspecified"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
PlatformPluginDirectorySubmissionCreated object
A plugin directory submission was created on the API platform. A plugin directory submission is a request to list a plugin in the public plugin directory.
type: optional "platform_plugin_directory_submission_created"
default: platform_plugin_directory_submission_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
plugin_name: string
The name of the plugin being submitted.
submission_id: string
The submission that was created, e.g. "psub_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformPluginDirectorySubmissionDeleted object
A plugin directory submission was deleted on the API platform.
type: optional "platform_plugin_directory_submission_deleted"
default: platform_plugin_directory_submission_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
submission_id: string
The submission that was deleted, e.g. "psub_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformPluginDirectorySubmissionUpdated object
A plugin directory submission was updated on the API platform.
type: optional "platform_plugin_directory_submission_updated"
default: platform_plugin_directory_submission_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
status: string
The submission's status after the update.
submission_id: string
The submission that was updated, e.g. "psub_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformServiceAccountArchived object
A service account was archived.
type: optional "platform_service_account_archived"
default: platform_service_account_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_account_id: string
Tagged ID of the archived service account
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformServiceAccountCreated object
A service account was created.
type: optional "platform_service_account_created"
default: platform_service_account_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
organization_role: string
Organization role the service account was created with — typically "admin" or "developer". A role this service does not recognize is recorded verbatim.
service_account_id: string
Tagged ID of the created service account, e.g. "svac_..."
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformServiceAccountUpdated object
A service account was updated.
type: optional "platform_service_account_updated"
default: platform_service_account_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_account_id: string
Tagged ID of the updated service account
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "description" or "organization_role" or "unspecified"
The service account field that changed
"description"
"organization_role"
"unspecified"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
PlatformServiceAccountWorkspaceMemberAdded object
A service account was added as a member of a workspace.
type: optional "platform_service_account_workspace_member_added"
default: platform_service_account_workspace_member_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_account_id: string
Tagged ID of the service account
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_role: optional string or null
Role the service account was given in the workspace, for example workspace_developer.
PlatformServiceAccountWorkspaceMemberRemoved object
A service account was removed from a workspace.
type: optional "platform_service_account_workspace_member_removed"
default: platform_service_account_workspace_member_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_account_id: string
Tagged ID of the service account
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformServiceAccountWorkspaceMemberUpdated object
A service account's workspace membership role was updated.
type: optional "platform_service_account_workspace_member_updated"
default: platform_service_account_workspace_member_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_account_id: string
Tagged ID of the service account
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "unspecified" or "workspace_role"
The service account's workspace membership field that changed
"unspecified"
"workspace_role"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
PlatformSigningKeyCreated object
Activity logged when a new request-signing key is registered for the org.
type: optional "platform_signing_key_created"
default: platform_signing_key_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
algorithm: string
The signing algorithm (e.g. ecdsa-p256-sha256)
key_backing_type: string
The backing type of the key (IN_MEMORY or CLOUD_KMS)
signing_key_id: string
The tagged ID of the created signing key
status: string
The initial status of the key (ACTIVE or PENDING)
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSigningKeyDeleted object
Activity logged when a signing key is permanently deleted.
type: optional "platform_signing_key_deleted"
default: platform_signing_key_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
algorithm: string
The algorithm of the deleted key
key_backing_type: string
The backing type of the deleted key (IN_MEMORY or CLOUD_KMS)
key_name: string
The name of the deleted key
signing_key_id: string
The tagged ID of the deleted signing key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSigningKeyRotated object
Activity logged when an in-memory signing key is rotated.
type: optional "platform_signing_key_rotated"
default: platform_signing_key_rotated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
algorithm: string
The algorithm of the new key
key_group_identifier: string
The key group identifier linking old and new keys
new_signing_key_id: string
The tagged ID of the newly created key
old_signing_key_id: string
The tagged ID of the expired old key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSkillVersionContentDownloaded object
The content of a track version was downloaded through the Tracks API.
type: optional "platform_skill_version_content_downloaded"
default: platform_skill_version_content_downloaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
skill_id: string
The tagged ID of the track
version: string
The version of the track whose content was downloaded
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSkillVersionCreated object
Activity logged when a track version is created via POST /v1/tracks/{skill_id}/versions.
type: optional "platform_skill_version_created"
default: platform_skill_version_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
skill_id: string
The tagged ID of the track
version: string
The version number of the created version
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSkillVersionDeleted object
Activity logged when a track version is deleted via DELETE /v1/tracks/{skill_id}/versions/{version}.
type: optional "platform_skill_version_deleted"
default: platform_skill_version_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
skill_id: string
The tagged ID of the track
version: string
The version number of the deleted version
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSpendLimitAlertEmailsUpdated object
Spend limit alert email addresses and role targets were updated for an org.
type: optional "platform_spend_limit_alert_emails_updated"
default: platform_spend_limit_alert_emails_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
alert_emails: optional array of string or null
Updated list of alert email addresses.
alerted_roles: optional array of string or null
Updated list of alerted roles.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSpendLimitCreated object
An org-level fixed-dollar spend limit was created.
type: optional "platform_spend_limit_created"
default: platform_spend_limit_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
limit_action: optional string or null
The action taken when the limit is reached (notify_only or notify_and_pause).
limit_usd: optional number or null
The spend limit threshold in USD cents.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformSpendLimitDeleted object
An org-level spend limit was removed.
type: optional "platform_spend_limit_deleted"
default: platform_spend_limit_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
UUID of the deleted spend limit.
PlatformSpendLimitUpdated object
An org-level spend limit snooze/ignore state was changed.
type: optional "platform_spend_limit_updated"
default: platform_spend_limit_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
ignore: optional boolean or null
Whether the limit is being snoozed (ignored).
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
UUID of the spend limit.
PlatformUsageReportHaijunCodeViewed object
The Haijun Code usage report was viewed.
type: optional "platform_usage_report_haijun_code_viewed"
default: platform_usage_report_haijun_code_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformUsageReportMessagesViewed object
The messages usage report was viewed.
type: optional "platform_usage_report_messages_viewed"
default: platform_usage_report_messages_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceArchived object
A workspace was archived.
type: optional "platform_workspace_archived"
default: platform_workspace_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
workspace_id: string
Tagged ID of the archived workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceCreated object
A workspace was created.
type: optional "platform_workspace_created"
default: platform_workspace_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
workspace_id: string
Tagged ID of the created workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceInferenceDataRetentionDisabled object
The zero data retention override was disabled for a workspace.
type: optional "platform_workspace_inference_data_retention_disabled"
default: platform_workspace_inference_data_retention_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Override state immediately before this change
PlatformWorkspaceInferenceDataRetentionEnabled object
The zero data retention override was enabled for a workspace.
type: optional "platform_workspace_inference_data_retention_enabled"
default: platform_workspace_inference_data_retention_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_value: optional boolean or null
Override state immediately before this change
PlatformWorkspaceMemberAdded object
A member was added to a workspace.
type: optional "platform_workspace_member_added"
default: platform_workspace_member_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
Tagged ID of the added member
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceMemberRemoved object
A member was removed from a workspace.
type: optional "platform_workspace_member_removed"
default: platform_workspace_member_removed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
Tagged ID of the removed member
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceMemberUpdated object
A workspace member was updated.
type: optional "platform_workspace_member_updated"
default: platform_workspace_member_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
Tagged ID of the updated member
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "unspecified" or "workspace_role"
The workspace member field that changed
"unspecified"
"workspace_role"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
PlatformWorkspaceMemberViewed object
A workspace member was viewed.
type: optional "platform_workspace_member_viewed"
default: platform_workspace_member_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
Tagged ID of the viewed member
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceMembersListed object
Workspace members were listed.
type: optional "platform_workspace_members_listed"
default: platform_workspace_members_listed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceRateLimitDeleted object
A workspace rate limit was deleted.
type: optional "platform_workspace_rate_limit_deleted"
default: platform_workspace_rate_limit_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
limiter_type: string
Type of rate limiter
model_group: string
Model group the rate limit applied to
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceRateLimitUpdated object
A workspace rate limit was created or updated.
type: optional "platform_workspace_rate_limit_updated"
default: platform_workspace_rate_limit_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
limiter_type: string
Type of rate limiter
model_group: string
Model group the rate limit applies to
value: number
New rate limit value
workspace_id: string
Tagged ID of the workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PlatformWorkspaceUpdated object
A workspace was updated.
type: optional "platform_workspace_updated"
default: platform_workspace_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
workspace_id: string
Tagged ID of the updated workspace
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "allowed_inference_geos" or "default_inference_geo" or "display_color" or 4 more
The workspace field that changed
"allowed_inference_geos"
"default_inference_geo"
"display_color"
"external_key_config_id"
"inference_data_retention"
"name"
"unspecified"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
HaijunPluginCreated object
Plugin was created.
type: optional "haijun_plugin_created"
default: haijun_plugin_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_id: optional string or null
plugin_name: optional string or null
HaijunPluginDeleted object
Plugin was deleted.
type: optional "haijun_plugin_deleted"
default: haijun_plugin_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_id: optional string or null
plugin_name: optional string or null
HaijunPluginDisabled object
User disabled a plugin for their account.
type: optional "haijun_plugin_disabled"
default: haijun_plugin_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
marketplace_id: optional string or null
Identifier of the marketplace the plugin was installed from.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_id: optional string or null
Identifier of the plugin that was disabled.
plugin_name: optional string or null
Name of the plugin that was disabled.
HaijunPluginEnabled object
User enabled a plugin for their account.
type: optional "haijun_plugin_enabled"
default: haijun_plugin_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
marketplace_id: optional string or null
Identifier of the marketplace the plugin was installed from.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_id: optional string or null
Identifier of the plugin that was enabled.
plugin_name: optional string or null
Name of the plugin that was enabled.
PluginInstallationPreferenceUpdated object
An org admin changed the installation preference for a plugin.
type: optional "plugin_installation_preference_updated"
default: plugin_installation_preference_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
marketplace_id: string
Marketplace ID
plugin_name: string
Plugin name
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
action: optional string or null
Action taken (e.g. 'deleted' for clearing an override)
created_at: optional string
When this activity occurred.
format: date-time
group_id: optional string or null
Tagged group ID for group-level overrides (null for org-level)
group_name: optional string or null
Group name for group-level overrides
installation_preference: optional string or null
New installation preference value (set only when action is an update; null for delete actions)
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_installation_preference: optional string or null
Installation preference value before this change, at the same level (organization or group); absent when none was set before
HaijunPluginReplaced object
Plugin was replaced.
type: optional "haijun_plugin_replaced"
default: haijun_plugin_replaced
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_id: optional string or null
plugin_name: optional string or null
HaijunPluginSecurityScanCompleted object
A security scan of a plugin completed and produced a verdict.
type: optional "haijun_plugin_security_scan_completed"
default: haijun_plugin_security_scan_completed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_id: string
Identifier of the security scan.
verdict: "fail" or "pass" or "unknown" or 2 more
Verdict the scan produced.
"fail"
"pass"
"unknown"
"unspecified"
"warn"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_id: optional string or null
Identifier of the plugin that was scanned.
plugin_name: optional string or null
Name of the plugin that was scanned.
plugin_version: optional string or null
Version of the plugin that was scanned.
HaijunPluginUpdated object
Plugin was updated.
type: optional "haijun_plugin_updated"
default: haijun_plugin_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plugin_id: optional string or null
plugin_name: optional string or null
PrepaidAutoRechargeDisabled object
Auto-recharge was disabled for API prepaid org.
type: optional "prepaid_auto_recharge_disabled"
default: prepaid_auto_recharge_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PrepaidAutoRechargeUpdated object
Auto-recharge settings were updated for API prepaid org.
type: optional "prepaid_auto_recharge_updated"
default: prepaid_auto_recharge_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
target_amount: optional number or null
Target recharge amount in minor units.
threshold_amount: optional number or null
Threshold amount to trigger recharge in minor units.
PrepaidExtraUsageAutoReloadDisabled object
Prepaid usage credit auto-reload was disabled.
type: optional "prepaid_extra_usage_auto_reload_disabled"
default: prepaid_extra_usage_auto_reload_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PrepaidExtraUsageAutoReloadEnabled object
Prepaid usage credit auto-reload was enabled.
type: optional "prepaid_extra_usage_auto_reload_enabled"
default: prepaid_extra_usage_auto_reload_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PrepaidExtraUsageAutoReloadSettingsUpdated object
Prepaid usage credit auto-reload settings were updated.
type: optional "prepaid_extra_usage_auto_reload_settings_updated"
default: prepaid_extra_usage_auto_reload_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
PrimaryOwnerTransferred object
Primary owner role was transferred to another org member.
type: optional "primary_owner_transferred"
default: primary_owner_transferred
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
new_owner_id: string
Tagged ID of the member who became the primary owner.
previous_owner_id: string
Tagged ID of the member who was the primary owner before the transfer.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectArchived object
A Haijun project was archived.
type: optional "haijun_project_archived"
default: haijun_project_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project that was archived, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectCreated object
A Haijun project was created.
type: optional "haijun_project_created"
default: haijun_project_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project that was created, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDeleted object
A Haijun project was deleted.
type: optional "haijun_project_deleted"
default: haijun_project_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project that was deleted, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDocumentAccessFailed object
An attempt to access a document in a Haijun project failed.
type: optional "haijun_project_document_access_failed"
default: haijun_project_document_access_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project the request targeted, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_document_id: optional string or null
Tagged ID of the document the request tried to access, e.g. "haijun_proj_doc_01HX...". Absent when the request did not carry a well-formed document identifier.
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the document, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDocumentBulkDeletionAuditTruncated object
A bulk request to delete documents from a Haijun project failed with more documents requested than were individually recorded in the audit log.
type: optional "haijun_project_document_bulk_deletion_audit_truncated"
default: haijun_project_document_bulk_deletion_audit_truncated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
audited_count: number
Number of documents that received an individual audit record.
haijun_project_id: string
Tagged ID of the project the bulk deletion targeted, e.g. "haijun_proj_01HX...".
requested_count: number
Total number of documents the request asked to delete.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDocumentDeleted object
A document was deleted from a Haijun project.
type: optional "haijun_project_document_deleted"
default: haijun_project_document_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_document_id: string
Tagged ID of the document that was deleted, e.g. "haijun_proj_doc_01HX...".
haijun_project_id: string
Tagged ID of the project the document was deleted from, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the deleted document, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDocumentDeletionFailed object
A request to delete a document from a Haijun project failed.
type: optional "haijun_project_document_deletion_failed"
default: haijun_project_document_deletion_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project the deletion targeted, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_project_document_id: optional string or null
Tagged ID of the document the deletion targeted, e.g. "haijun_proj_doc_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the document, when known.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDocumentUpdated object
The content of a document in a Haijun project was replaced in place.
type: optional "haijun_project_document_updated"
default: haijun_project_document_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_document_id: string
Tagged ID of the document whose content was replaced, e.g. "haijun_proj_doc_01HX...".
haijun_project_id: string
Tagged ID of the project containing the document, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the updated document.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDocumentUploaded object
A document was uploaded to a Haijun project.
type: optional "haijun_project_document_uploaded"
default: haijun_project_document_uploaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_document_id: string
Tagged ID of the document that was uploaded, e.g. "haijun_proj_doc_01HX...".
haijun_project_id: string
Tagged ID of the project the document was uploaded to, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the uploaded document.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectDocumentViewed object
A document in a Haijun project was viewed.
type: optional "haijun_project_document_viewed"
default: haijun_project_document_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_document_id: string
Tagged ID of the document that was viewed, e.g. "haijun_proj_doc_01HX...".
haijun_project_id: string
Tagged ID of the project containing the document, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the viewed document.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectFileAccessFailed object
An attempt to access a file in a Haijun project failed.
type: optional "haijun_project_file_access_failed"
default: haijun_project_file_access_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_file_id: string
Tagged ID of the file the request tried to access, e.g. "haijun_file_01HX...".
haijun_project_id: string
Tagged ID of the project the request targeted, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectFileBulkDeletionAuditTruncated object
A bulk request to delete files from a Haijun project failed with more files requested than were individually recorded in the audit log.
type: optional "haijun_project_file_bulk_deletion_audit_truncated"
default: haijun_project_file_bulk_deletion_audit_truncated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
audited_count: number
Number of files that received an individual audit record.
haijun_project_id: string
Tagged ID of the project the bulk deletion targeted, e.g. "haijun_proj_01HX...".
requested_count: number
Total number of files the request asked to delete.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectFileDeleted object
A file was deleted from a Haijun project.
type: optional "haijun_project_file_deleted"
default: haijun_project_file_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_file_id: string
Tagged ID of the file that was deleted, e.g. "haijun_file_01HX...".
haijun_project_id: string
Tagged ID of the project the file was deleted from, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectFileDeletionFailed object
A request to delete a file from a Haijun project failed.
type: optional "haijun_project_file_deletion_failed"
default: haijun_project_file_deletion_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project the deletion targeted, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
haijun_file_id: optional string or null
Tagged ID of the file that was not deleted, e.g. "haijun_file_01HX...".
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectFileUploaded object
A file was uploaded to a Haijun project.
type: optional "haijun_project_file_uploaded"
default: haijun_project_file_uploaded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_file_id: string
Tagged ID of the file that was uploaded, e.g. "haijun_file_01HX...".
haijun_project_id: string
Tagged ID of the project the file was uploaded to, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
filename: optional string or null
Name of the uploaded file.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectReported object
A Haijun project was reported.
type: optional "haijun_project_reported"
default: haijun_project_reported
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project that was reported, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectSharingUpdated object
A Haijun project's sharing settings were updated.
type: optional "haijun_project_sharing_updated"
default: haijun_project_sharing_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
audience: array of Public or Organization
Sharing audience for the project. If empty, it's only visible to the creating user.
Public object
Sharing audience: public.
type: optional "public"
default: public
Organization object
Sharing audience: the project is visible to members of the owning organization.
type: optional "organization"
default: organization
haijun_project_id: string
The project's identifier, e.g. "haijun_proj_01Ab...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunProjectViewed object
A Haijun project was viewed.
type: optional "haijun_project_viewed"
default: haijun_project_viewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
haijun_project_id: string
Tagged ID of the project that was viewed, e.g. "haijun_proj_01HX...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
preview_only: optional boolean or null
Whether only the project's summary metadata was viewed rather than the full project.
HaijunPubsecIdentityConfigured object
SAML IdP configuration updated for a public sector organization.
type: optional "haijun_pubsec_identity_configured"
default: haijun_pubsec_identity_configured
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
idp_saml_config_updated: boolean
magic_link_toggled: boolean
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
magic_link_enabled: optional boolean or null
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRoleAssigned object
Admin assigned an RBAC custom role to a principal.
type: optional "rbac_role_assigned"
default: rbac_role_assigned
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
principal_id: string
Tagged ID of the principal
principal_type: string
Type of principal: account, group, or service_account
role_id: string
Tagged ID of the role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRoleCreated object
Admin created an RBAC custom role.
type: optional "rbac_role_created"
default: rbac_role_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
role_id: string
Tagged ID of the created role
role_name: string
Name of the created role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRoleDeleted object
Admin deleted an RBAC custom role.
type: optional "rbac_role_deleted"
default: rbac_role_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
role_id: string
Tagged ID of the deleted role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRoleGrantUpdated object
Admin requested a capability grant for an RBAC custom role, or removed it.
Records the admin's change to the role. Whether the grant is currently in effect on the role is reported separately.
type: optional "rbac_role_grant_updated"
default: rbac_role_grant_updated
action: "removed" or "requested" or "unspecified"
Whether the grant was requested for the role or removed from it
"removed"
"requested"
"unspecified"
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
grant_type: string
The type of capability grant
role_id: string
Tagged ID of the role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRolePermissionAdded object
Admin added a permission to an RBAC custom role.
Emitted once per requested permission, including permissions the role already had, so a retried request still produces a complete audit record.
type: optional "rbac_role_permission_added"
default: rbac_role_permission_added
action: string
Action permitted on the resource
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resource_id: string
ID of the resource
resource_type: string
Type of resource the permission applies to
role_id: string
Tagged ID of the role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRolePermissionRemoved object
Admin removed a permission from an RBAC custom role.
Emitted once per requested permission, including permissions the role already lacked, so a retried request still produces a complete audit record.
type: optional "rbac_role_permission_removed"
default: rbac_role_permission_removed
action: string
Action that was permitted on the resource
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
resource_id: string
ID of the resource
resource_type: string
Type of resource the permission applied to
role_id: string
Tagged ID of the role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRoleUnassigned object
Admin unassigned an RBAC custom role from a principal.
type: optional "rbac_role_unassigned"
default: rbac_role_unassigned
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
principal_id: string
Tagged ID of the principal
principal_type: string
Type of principal: account, group, or service_account
role_id: string
Tagged ID of the role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RbacRoleUpdated object
Admin updated an RBAC custom role.
type: optional "rbac_role_updated"
default: rbac_role_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
role_id: string
Tagged ID of the updated role
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
RoleAssignmentGranted object
Role assignment was granted.
type: optional "role_assignment_granted"
default: role_assignment_granted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
resource_id: optional string or null
ID of the resource the role is on.
resource_type: optional string or null
What kind of resource the role is on, for example "chat_project", "track", or "plugin".
role: optional string or null
The role that was granted, for example "track:viewer" or "plugin:viewer".
target_email: optional string or null
Email address of the person who received the role when they are an invitee identified by email address or an account outside the organization; absent or null for members and groups.
target_id: optional string or null
ID of the grantee: a user ID for a member or for an account outside the organization, a group ID for a group, the organization ID for an organization-wide grant, or an opaque "email:" key for an invitee identified only by email address.
target_type: optional string or null
What kind of grantee received the role, for example "organization_member", "group", "organization", "account" (an account outside the organization), or "email" (an invitee identified by email address).
RoleAssignmentRevoked object
Role assignment was revoked.
type: optional "role_assignment_revoked"
default: role_assignment_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
resource_id: optional string or null
ID of the resource the role was on.
resource_type: optional string or null
What kind of resource the role was on, for example "chat_project", "track", or "plugin".
role: optional string or null
The role that was revoked, for example "track:viewer" or "plugin:viewer".
target_email: optional string or null
Email address of the person who held the role when they are an invitee identified by email address or an account outside the organization; absent or null for members and groups.
target_id: optional string or null
ID of the grantee that held the role: a user ID for a member or for an account outside the organization, a group ID for a group, the organization ID for an organization-wide grant, or an opaque "email:" key for an invitee identified only by email address.
target_type: optional string or null
What kind of grantee held the role, for example "organization_member", "group", "organization", "account" (an account outside the organization), or "email" (an invitee identified by email address).
SSOLoginFailed object
An SSO sign-in attempt failed.
type: optional "sso_login_failed"
default: sso_login_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SSOLoginInitiated object
A user started an SSO sign-in flow.
type: optional "sso_login_initiated"
default: sso_login_initiated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SSOLoginSucceeded object
A user successfully signed in with SSO.
type: optional "sso_login_succeeded"
default: sso_login_succeeded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
auth_method: optional "sso" or "unspecified" or null
The method the user used to authenticate. May be absent on activities recorded before this field was introduced.
"sso"
"unspecified"
created_at: optional string
When this activity occurred.
format: date-time
mfa_method: optional "not_used" or "unspecified" or null
The second authentication factor performed during this login, if any. null when the second-factor status is not recorded on this event — for example, when authentication was delegated to an external identity provider and any second factor is not visible to Juglow, or when this event is one step of a multistep login whose MFA is reported on another activity. May be absent on activities recorded before this field was introduced.
"not_used"
"unspecified"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SSOSecondFactorMagicLink object
SSO second factor magic link was used.
type: optional "sso_second_factor_magic_link"
default: sso_second_factor_magic_link
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ScimUserCreated object
A SCIM user was provisioned.
type: optional "scim_user_created"
default: scim_user_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ScimUserDeleted object
A SCIM user was deleted.
type: optional "scim_user_deleted"
default: scim_user_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ScimUserUpdated object
A SCIM user was updated.
type: optional "scim_user_updated"
default: scim_user_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ScopedAPIKeyDeleted object
A scoped API key was deleted.
type: optional "scoped_api_key_deleted"
default: scoped_api_key_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
api_key_id: string
Tagged ID of the deleted scoped API key
api_key_name: string
Name of the deleted scoped API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scopes: optional array of string
Scopes the deleted key had
ScopedAPIKeyUpdated object
A scoped API key was renamed or its activation state changed.
type: optional "scoped_api_key_updated"
default: scoped_api_key_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
api_key_id: string
Tagged ID of the updated scoped API key
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
updates: optional array of object
The field-level changes applied in this update
type: "activation_state" or "name" or "unspecified"
The scoped API key field that changed
"activation_state"
"name"
"unspecified"
current_value: string
Field value immediately after this change
previous_value: string
Field value immediately before this change
SeatTierChangesCancelled object
Scheduled seat tier downgrades were cancelled.
type: optional "seat_tier_changes_cancelled"
default: seat_tier_changes_cancelled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SeatTiersPurchased object
Seat tiers were purchased or upgraded on a subscription.
type: optional "seat_tiers_purchased"
default: seat_tiers_purchased
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
item_allocations: optional map[number] or null
Desired seat tier allocations (item type to quantity).
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ServiceCreated object
Activity logged when an org service is explicitly created.
type: optional "service_created"
default: service_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_name: string
The org service name (e.g., 'external:my-service')
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ServiceDeleted object
Activity logged when an org service is deleted.
type: optional "service_deleted"
default: service_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_name: string
The org service name (e.g., 'external:my-service')
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
ServiceKeyCreated object
Activity logged when a new org service key is created.
type: optional "service_key_created"
default: service_key_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
is_service_created: boolean
Whether the org service was implicitly created in this request
key_name: string
The human-readable name of the key
service_name: string
The service name this key belongs to
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scopes: optional array of string
The scopes granted to this service key
service_key_id: optional string or null
The ID of the created service key
ServiceKeyRevoked object
Activity logged when an org service key is revoked.
type: optional "service_key_revoked"
default: service_key_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
service_key_id: string
The tagged ID of the revoked service key
service_name: string
The service name this key belongs to
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SessionRevoked object
User revoked a specific session.
type: optional "session_revoked"
default: session_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SessionShareAccessed object
Session share was accessed.
type: optional "session_share_accessed"
default: session_share_accessed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
share_id: optional string or null
SessionShareCreated object
Session share was created.
type: optional "session_share_created"
default: session_share_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
access_level: optional string or null
Access level granted for the share.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
share_id: optional string or null
SessionShareRevoked object
Session share was revoked.
type: optional "session_share_revoked"
default: session_share_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
reason: optional string or null
Why the share was revoked.
share_id: optional string or null
HaijunSkillCreated object
Track was created.
type: optional "haijun_skill_created"
default: haijun_skill_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
owner_user_id: optional string or null
The member who owns the track; unset for an organization-owned track.
scope: optional "organization" or "personal" or "unspecified" or null
Whether the track is the member's own or the organization's.
"organization"
"personal"
"unspecified"
skill_id: optional string or null
skill_name: optional string or null
skill_version: optional string or null
Version of the track that was created.
HaijunSkillDeleted object
Track was deleted.
type: optional "haijun_skill_deleted"
default: haijun_skill_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
deleted_version_ids: optional array of string
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
owner_user_id: optional string or null
The member who owns the track; unset for an organization-owned track.
scope: optional "organization" or "personal" or "unspecified" or null
Whether the track is the member's own or the organization's.
"organization"
"personal"
"unspecified"
skill_id: optional string or null
skill_name: optional string or null
skill_version: optional string or null
Latest version of the track when it was deleted.
versions_deleted: optional number or null
Set when the deletion removed the track's versions in the same request (the public API's cascading track delete): one consolidated record of what went with the track, reconcilable against earlier version-created records, rather than one version-deleted activity per row. versions_deleted is the exact count; deleted_version_ids lists at most the newest 1000 (truncated when versions_deleted exceeds its length).
HaijunSkillDisabled object
User disabled a track for their account.
type: optional "haijun_skill_disabled"
default: haijun_skill_disabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
skill_id: optional string or null
skill_name: optional string or null
HaijunSkillEnabled object
User enabled a track for their account.
type: optional "haijun_skill_enabled"
default: haijun_skill_enabled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
skill_id: optional string or null
skill_name: optional string or null
HaijunSkillReplaced object
Track was replaced.
type: optional "haijun_skill_replaced"
default: haijun_skill_replaced
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
owner_user_id: optional string or null
The member who owns the track; unset for an organization-owned track.
scope: optional "organization" or "personal" or "unspecified" or null
Whether the track is the member's own or the organization's.
"organization"
"personal"
"unspecified"
skill_id: optional string or null
skill_name: optional string or null
skill_version: optional string or null
Version of the track after it was replaced.
HaijunSkillSecurityScanCompleted object
A security scan of a track completed and produced a verdict.
type: optional "haijun_skill_security_scan_completed"
default: haijun_skill_security_scan_completed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
scan_id: string
Identifier of the security scan.
verdict: "fail" or "pass" or "unknown" or 2 more
Verdict the scan produced.
"fail"
"pass"
"unknown"
"unspecified"
"warn"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
skill_id: optional string or null
Identifier of the track that was scanned.
skill_name: optional string or null
Name of the track that was scanned.
skill_version: optional string or null
Version of the track that was scanned.
SlackWorkspaceClaimRevoked object
A Slack workspace or Enterprise Grid organization was disconnected from the organization for Haijun in Slack.
type: optional "slack_workspace_claim_revoked"
default: slack_workspace_claim_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
slack_team_id: string
Claim subject: a Slack team id for scope 'workspace', or an Enterprise Grid org id for scope 'enterprise_grid'. Use the scope field to tell which — never the value's prefix (legacy workspaces exist with E-prefixed team ids)
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scope: optional string or null
Blast radius of the revocation: 'workspace' for one Slack workspace, 'enterprise_grid' for every workspace in a Slack Enterprise Grid organization
SlackWorkspaceClaimed object
A Slack workspace or Enterprise Grid organization was connected to the organization for Haijun in Slack.
type: optional "slack_workspace_claimed"
default: slack_workspace_claimed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
slack_team_id: string
Claim subject: a Slack team id for scope 'workspace', or an Enterprise Grid org id for scope 'enterprise_grid'. Use the scope field to tell which — never the value's prefix (legacy workspaces exist with E-prefixed team ids)
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
scope: optional string or null
Blast radius of the claim: 'workspace' for one Slack workspace, 'enterprise_grid' for every workspace in a Slack Enterprise Grid organization
SocialLoginSucceeded object
A user successfully signed in with a social identity provider (Google, Apple, or Microsoft).
type: optional "social_login_succeeded"
default: social_login_succeeded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
provider: "apple" or "google" or "microsoft" or "unspecified"
The social identity provider the user signed in with: "google", "apple", or "microsoft".
"apple"
"google"
"microsoft"
"unspecified"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
auth_method: optional "social" or "unspecified" or null
The method the user used to authenticate. May be absent on activities recorded before this field was introduced.
"social"
"unspecified"
created_at: optional string
When this activity occurred.
format: date-time
mfa_method: optional "not_used" or "unspecified" or null
The second authentication factor performed during this login, if any. null when the second-factor status is not recorded on this event — for example, when authentication was delegated to an external identity provider and any second factor is not visible to Juglow, or when this event is one step of a multistep login whose MFA is reported on another activity. May be absent on activities recorded before this field was introduced.
"not_used"
"unspecified"
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
StepUpAuthenticationFailed object
An additional identity check failed.
type: optional "step_up_authentication_failed"
default: step_up_authentication_failed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
method: "device_key" or "unspecified" or "webauthn"
The verification method the user attempted.
"device_key"
"unspecified"
"webauthn"
reason: "challenge_rejected" or "unspecified" or "verification_failed"
Why the attempt failed.
"challenge_rejected"
"unspecified"
"verification_failed"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
trusted_device_id: optional string or null
Identifier of the trusted device the attempt referenced, e.g. "tdev_...". Present only for the device key method.
StepUpAuthenticationSucceeded object
The user completed an additional identity check to confirm a sensitive action.
type: optional "step_up_authentication_succeeded"
default: step_up_authentication_succeeded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
method: "device_key" or "unspecified" or "webauthn"
The verification method the user completed.
"device_key"
"unspecified"
"webauthn"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
trusted_device_id: optional string or null
Identifier of the trusted device used, e.g. "tdev_...". Present only for the device key method.
StepUpCredentialEnrolled object
A user enrolled a passkey for confirming sensitive actions on their account.
type: optional "step_up_credential_enrolled"
default: step_up_credential_enrolled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
credential_id: string
Identifier of the enrolled credential, e.g. "sucr_...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SubscriptionCancellationScheduled object
Subscription cancellation was scheduled at end of billing period.
type: optional "subscription_cancellation_scheduled"
default: subscription_cancellation_scheduled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SubscriptionQuantityUpdated object
Contracted subscription seat quantity was updated.
type: optional "subscription_quantity_updated"
default: subscription_quantity_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
added_seats: number
The number of seats added by this change.
new_quantity: number
The contracted seat quantity after this change.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_quantity: optional number or null
The contracted seat quantity before this change.
SubscriptionRenewed object
A cancelled subscription was renewed.
type: optional "subscription_renewed"
default: subscription_renewed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
billing_interval: optional string or null
Billing interval (e.g. monthly, annual).
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plan_type: optional string or null
Plan type being renewed into (e.g. team).
SubscriptionResumed object
A scheduled subscription cancellation was reversed.
type: optional "subscription_resumed"
default: subscription_resumed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
SubscriptionStarted object
A new subscription was created (Team or Enterprise).
type: optional "subscription_started"
default: subscription_started
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
billing_interval: optional string or null
Billing interval (e.g. monthly, annual).
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
plan_type: optional string or null
Type of subscription started (e.g. team, enterprise).
seat_count: optional number or null
Number of seats purchased.
SubscriptionUpgraded object
Subscription plan was upgraded (e.g. Team to Enterprise).
type: optional "subscription_upgraded"
default: subscription_upgraded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
new_plan: optional string or null
New plan type after upgrade.
old_plan: optional string or null
Previous plan type.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
TrustedDeviceCredentialRotated object
The identity-verification credential of a trusted device was rotated to a new key.
type: optional "trusted_device_credential_rotated"
default: trusted_device_credential_rotated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
trusted_device_id: string
Identifier of the device whose credential was rotated, e.g. "tdev_...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
TrustedDeviceEnrolled object
A device was enrolled as a trusted device for the user's account. Trusted devices can be used to confirm the user's identity for sensitive actions.
type: optional "trusted_device_enrolled"
default: trusted_device_enrolled
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
enrollment_method: "oauth" or "session" or "unspecified"
How the user confirmed their identity when enrolling the device.
"oauth"
"session"
"unspecified"
platform: "android" or "haijun_in_slack" or "desktop_app" or 4 more
The kind of client the enrollment request came from.
"android"
"haijun_in_slack"
"desktop_app"
"ios"
"unspecified"
"web_haijun_ai"
"web_console"
trusted_device_id: string
Identifier of the device that was enrolled, e.g. "tdev_...".
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
TrustedDeviceRevoked object
A trusted device was removed from the user's account.
type: optional "trusted_device_revoked"
default: trusted_device_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
reason: "org_member_removed" or "superseded" or "unspecified" or "user_revoked"
Why the device trust was removed.
"org_member_removed"
"superseded"
"unspecified"
"user_revoked"
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
revoked_count: optional number or null
Number of devices removed. Set when a security action removed all of the user's trusted devices at once; absent when a single device was removed (see trusted_device_id).
trusted_device_id: optional string or null
Identifier of the device that was removed, e.g. "tdev_...". Set when a single device was removed; absent when several devices were removed at once (see revoked_count).
TunnelArchived object
An MCP tunnel was archived.
type: optional "tunnel_archived"
default: tunnel_archived
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
tunnel_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
TunnelCertificateAdded object
An inner-TLS CA certificate was added to a tunnel.
type: optional "tunnel_certificate_added"
default: tunnel_certificate_added
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
certificate_id: string
tunnel_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
certificate_fingerprint: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
TunnelCertificateRevoked object
An inner-TLS CA certificate was revoked from a tunnel.
type: optional "tunnel_certificate_revoked"
default: tunnel_certificate_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
certificate_id: string
tunnel_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
certificate_fingerprint: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
TunnelCreated object
An MCP tunnel was created.
type: optional "tunnel_created"
default: tunnel_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
tunnel_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
tunnel_token_id: optional string or null
Id of the tunnel token issued with the tunnel and returned once in the create response; set only when creating the tunnel also issued its token, and absent for a tunnel whose token is revealed separately
TunnelTokenMinted object
An OAuth bearer token for the tunnel management API was minted.
type: optional "tunnel_token_minted"
default: tunnel_token_minted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
token_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
token_name: optional string or null
TunnelTokenRevealed object
The Cloudflare connector secret for a tunnel was revealed to the caller.
type: optional "tunnel_token_revealed"
default: tunnel_token_revealed
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
tunnel_id: string
tunnel_token_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
TunnelTokenRevoked object
An OAuth bearer token for the tunnel management API was revoked.
type: optional "tunnel_token_revoked"
default: tunnel_token_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
token_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
token_name: optional string or null
Name the administrator gave the token when it was created, if any
TunnelTokenRotated object
The Cloudflare connector secret for a tunnel was rotated.
tunnel_token_id is the id of the newly-issued token. The previous token is invalidated by the rotation and its id is not recorded here.
type: optional "tunnel_token_rotated"
default: tunnel_token_rotated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
tunnel_id: string
tunnel_token_id: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
reason: optional string or null
UserConsentRecorded object
User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).
type: optional "user_consent_recorded"
default: user_consent_recorded
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
consent_type: string
entity_id: string
entity_type: string
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
UserConsentRevoked object
User revoked a previously granted consent for a specific entity.
type: optional "user_consent_revoked"
default: user_consent_revoked
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
consent_id: optional string or null
consent_type: optional string or null
created_at: optional string
When this activity occurred.
format: date-time
entity_id: optional string or null
entity_type: optional string or null
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
HaijunUserRoleUpdated object
A user's role within the organization was changed, or the user was added to or removed from the organization.
type: optional "haijun_user_role_updated"
default: haijun_user_role_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
user_email: string
Email of the user whose role was changed
user_id: string
ID of the user whose role was changed
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
current_role: optional string or null
If null, then user was removed from the Organization
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
previous_role: optional string or null
If null, then user was added to the Organization
HaijunUserSettingsUpdated object
User updated their personal settings.
type: optional "haijun_user_settings_updated"
default: haijun_user_settings_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
updates: array of FullName or DisplayName or ArtifactsEnabled or 19 more
FullName object
The full name setting was changed.
type: optional "full_name"
default: full_name
current_value: optional string or null
Setting value immediately after this change
previous_value: optional string or null
Setting value immediately before this change
DisplayName object
The display name setting was changed.
type: optional "display_name"
default: display_name
current_value: optional string or null
Setting value immediately after this change
previous_value: optional string or null
Setting value immediately before this change
ArtifactsEnabled object
The artifacts setting was changed.
type: optional "artifacts_enabled"
default: artifacts_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
LatexEnabled object
The LaTeX setting was changed.
type: optional "latex_enabled"
default: latex_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
AnalysisToolEnabled object
The analysis tool setting was changed.
type: optional "analysis_tool_enabled"
default: analysis_tool_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
ChatSuggestionsEnabled object
The chat suggestions setting was changed.
type: optional "chat_suggestions_enabled"
default: chat_suggestions_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
MultimodalPdfsEnabled object
The multimodal PDFs setting was changed.
type: optional "multimodal_pdfs_enabled"
default: multimodal_pdfs_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
GdriveEnabled object
The Google Drive setting was changed.
type: optional "gdrive_enabled"
default: gdrive_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
WebSearchEnabled object
The web search setting was changed.
type: optional "web_search_enabled"
default: web_search_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
GeolocationEnabled object
The geolocation setting was changed.
type: optional "geolocation_enabled"
default: geolocation_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
EnabledSaffron object
The memory setting was changed for the user.
type: optional "enabled_saffron"
default: enabled_saffron
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
McpToolsEnabled object
The MCP tools setting was changed.
type: optional "mcp_tools_enabled"
default: mcp_tools_enabled
current_value: optional map[boolean] or null
Setting value immediately after this change
previous_value: optional map[boolean] or null
Setting value immediately before this change
CliOpPermissionsEnabled object
The CLI operation permissions setting was changed.
type: optional "cli_op_permissions_enabled"
default: cli_op_permissions_enabled
current_value: optional map[string] or null
Setting value immediately after this change
previous_value: optional map[string] or null
Setting value immediately before this change
GoogleDriveSearchEnabled object
The Google Drive search setting was changed.
type: optional "google_drive_search_enabled"
default: google_drive_search_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
GmailIntegrationEnabled object
The Gmail integration setting was changed.
type: optional "gmail_integration_enabled"
default: gmail_integration_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
GoogleCalendarIntegrationEnabled object
The Google Calendar integration setting was changed.
type: optional "google_calendar_integration_enabled"
default: google_calendar_integration_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
ThinkingModeEnabled object
The thinking mode setting was changed.
type: optional "thinking_mode_enabled"
default: thinking_mode_enabled
current_value: optional "adaptive" or "extended" or "off" or "unspecified" or null
Setting value immediately after this change
"adaptive"
"extended"
"off"
"unspecified"
previous_value: optional "adaptive" or "extended" or "off" or "unspecified" or null
Setting value immediately before this change
"adaptive"
"extended"
"off"
"unspecified"
ResearchModeEnabled object
The research mode setting was changed.
type: optional "research_mode_enabled"
default: research_mode_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
ComputerUseEnabled object
The computer use setting was changed.
type: optional "computer_use_enabled"
default: computer_use_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
HaijunAPIInArtifactsEnabled object
The Haijun API in Artifacts setting was changed.
type: optional "haijun_api_in_artifacts_enabled"
default: haijun_api_in_artifacts_enabled
current_value: optional boolean or null
Setting value immediately after this change
previous_value: optional boolean or null
Setting value immediately before this change
ConversationPreferences object
The 'conversation_preferences' for the user were updated. Values omitted.
type: optional "conversation_preferences"
default: conversation_preferences
CoworkGlobalInstructions object
The Cowork global instructions were updated. Values omitted.
type: optional "cowork_global_instructions"
default: cowork_global_instructions
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
VerificationEvidenceSubmitted object
Verification evidence was submitted for an organization's verification.
type: optional "verification_evidence_submitted"
default: verification_evidence_submitted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
verification_id: string
Tagged ID of the verification the evidence was submitted for.
verification_type: string
The type of verification the evidence was submitted for.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
VerificationProgramApplicationCreated object
An organization applied to a verification program.
type: optional "verification_program_application_created"
default: verification_program_application_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
program_slug: string
The verification program the organization applied to.
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
WorkspaceMemberSpendLimitCreated object
A per-member or workspace-default Haijun Code spend limit was created.
type: optional "workspace_member_spend_limit_created"
default: workspace_member_spend_limit_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
account_id: optional string or null
Tagged ID of the user (null for workspace-wide default).
created_at: optional string
When this activity occurred.
format: date-time
limit_action: optional string or null
The action taken when the limit is reached.
limit_usd: optional number or null
The spend limit threshold in USD cents.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace.
WorkspaceMemberSpendLimitDeleted object
A per-member or workspace-default Haijun Code spend limit was deleted.
type: optional "workspace_member_spend_limit_deleted"
default: workspace_member_spend_limit_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
account_id: optional string or null
Tagged ID of the user (null for workspace-wide default).
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
UUID of the deleted spend limit.
workspace_id: optional string or null
Tagged ID of the workspace.
WorkspaceMemberSpendLimitUpdated object
A per-member Haijun Code spend limit amount was updated.
type: optional "workspace_member_spend_limit_updated"
default: workspace_member_spend_limit_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
account_id: optional string or null
Tagged ID of the user (null for workspace-wide default).
created_at: optional string
When this activity occurred.
format: date-time
new_limit_usd: optional number or null
The new spend limit threshold in USD cents.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
UUID of the spend limit.
workspace_id: optional string or null
Tagged ID of the workspace.
WorkspaceSpendLimitAlertEmailsUpdated object
Spend limit alert email recipients were updated for a workspace.
type: optional "workspace_spend_limit_alert_emails_updated"
default: workspace_spend_limit_alert_emails_updated
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
alert_emails: optional array of string or null
Updated list of alert email addresses.
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace.
WorkspaceSpendLimitCreated object
A workspace-level API spend limit was created.
type: optional "workspace_spend_limit_created"
default: workspace_spend_limit_created
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
limit_action: optional string or null
The action taken when the limit is reached (notify_only or notify_and_pause).
limit_usd: optional number or null
The spend limit threshold in USD cents.
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
workspace_id: optional string or null
Tagged ID of the workspace.
WorkspaceSpendLimitDeleted object
A workspace-level API spend limit was deleted.
type: optional "workspace_spend_limit_deleted"
default: workspace_spend_limit_deleted
actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more
APIActor object
type: optional "api_actor"
default: api_actor
api_key_id: string
ip_address: string
user_agent: string
UserActor object
type: optional "user_actor"
default: user_actor
email_address: string
format: email
ip_address: string
user_agent: string
user_id: string
UnauthenticatedUserActor object
type: optional "unauthenticated_user_actor"
default: unauthenticated_user_actor
ip_address: string
user_agent: string
unauthenticated_email_address: optional string or null
format: email
JuglowActor object
type: optional "juglow_actor"
default: juglow_actor
email_address: optional string or null
format: email
SystemActor object
Automated background processing performed by Juglow systems, acting without a user or customer credential.
type: optional "system_actor"
default: system_actor
service: optional string or null
Name of the automated process that performed the action, when known.
AdminAPIKeyActor object
type: optional "admin_api_key_actor"
default: admin_api_key_actor
admin_api_key_id: string
ip_address: string
user_agent: string
ServiceAccountActor object
type: optional "service_account_actor"
default: service_account_actor
ip_address: string
service_account_id: string
user_agent: string
ScimDirectorySyncActor object
type: optional "scim_directory_sync_actor"
default: scim_directory_sync_actor
directory_id: string
workos_event_id: string
idp_connection_type: optional string or null
FederatedIdentityActor object
A federated external workload authenticated via a verified OIDC token.
Carries the verified issuer, subject, and audience claims from the presented JWT.
type: optional "federated_identity_actor"
default: federated_identity_actor
issuer: string
subject: string
audience: optional array of string
ip_address: optional string or null
user_agent: optional string or null
FederatedActor object
An external identity asserted by a trusted provider — a cloud-provider gateway or a customer-registered federation issuer — acting without an Juglow-provisioned account or service account.
type: optional "federated_actor"
default: federated_actor
provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider
FederatedActorAwsProvider object
Asserting party: the AWS account the organization is bound to.
type: optional "aws"
default: aws
account_id: string
signed_principal: string
The AWS-signed ARN of the IAM principal that requested the token.
FederatedActorAzureProvider object
Asserting party: the Azure subscription the organization is bound to.
type: optional "azure"
default: azure
subscription_id: string
FederatedActorGcpProvider object
Asserting party: the GCP project the organization is bound to.
type: optional "gcp"
default: gcp
project_number: string
FederatedActorOidcProvider object
Asserting party: a customer-registered OIDC federation issuer.
type: optional "oidc"
default: oidc
issuer: optional string or null
The federation issuer's URL. Null when the presented credential failed verification.
ip_address: optional string or null
subject: optional string or null
The provider's verified identifier for the caller; its form depends on the provider.
user_agent: optional string or null
AttestedDeviceActor object
An attested mobile device authenticated via Apple App Attest.
type: optional "attested_device_actor"
default: attested_device_actor
external_client_id: string
kid_hash: string
ip_address: optional string or null
user_agent: optional string or null
id: optional string
Unique identifier for the activity e.g. 'activity_abcd1234'
created_at: optional string
When this activity occurred.
format: date-time
organization_id: optional string or null
Organization ID this activity is associated with
organization_uuid: optional string or null
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
spend_limit_id: optional string or null
UUID of the deleted spend limit.
workspace_id: optional string or null
Tagged ID of the workspace.
first_id: optional string or null
has_more: optional boolean
default: false
last_id: optional string or null
Example
curl https://haijun.my.id/v1/compliance/activities \
-H 'juglow-version: 2023-06-01' \
-H "Authorization: Bearer $JUGLOW_COMPLIANCE_API_KEY"Response (200)
{
"data": [
{
"actor": {
"api_key_id": "api_key_id",
"ip_address": "ip_address",
"user_agent": "user_agent",
"type": "api_actor"
},
"decision": "blocked",
"id": "id",
"abuse_session_id": "abuse_session_id",
"created_at": "2019-12-27T18:11:19.117Z",
"organization_id": "organization_id",
"organization_uuid": "organization_uuid",
"type": "abuse_decision_received"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}