Audit Monitoring

Hudu's activity logs track and store every action a user can perform within your Hudu environment. Activity logs are immutable: once an entry is created, it cannot be modified or deleted by any user or administrator. Audit logs for individual records are also linked to their revision histories, giving you full visibility into changes and consistent traceability across the platform. All activity and audit log data is retained indefinitely, providing an unalterable record that upholds data integrity.

   The Hudu admin area is accessible only to admin and super admin users within your organization.

   Only super admin roles can view the global and item-specific activity logs.

Guides

Accessing item-specific activity logs

Activity logs are kept for each individual item stored within Hudu, such as a specific password, KB article, or custom asset.

  • To view all activity performed on a single item stored within one of your client spaces, navigate to the item.
  • In the right-hand side menu, scroll to the bottom and find Activity Feed.
  • The feed displays a log filtered to only include actions performed on the specific item, along with who or what performed each action.
  • Super admins and admins will see an option to select View All Activity. This opens all logged activity for that item, including the action, user or source, date/time, and IP address.

    Activity logs are kept for every individual item stored within Hudu, with the exception of processes and expirations.

Accessing global activity logs

  • To view all activity performed on every item within your Hudu environment, navigate to the Hudu admin area >> Activity Logs.
  • This provides a log of all actions performed on any item stored within your Hudu environment, regardless of which client space it resides in.
  • You can additionally filter by:
    • Client name
    • Action (performed)
    • User (who or what performed the action)
    • Date/Time (when the action was performed)
    • IP Address (from which the action was performed)

Understanding activity log attribution

Activity log entries name the specific source behind automated, programmatic, and AI-driven changes. Instead of attributing these changes to HuduBot, entries show exactly what made the change:

  • API key: the specific API key used to make the request.
  • Integration: the integration that created or updated the record.
  • Import: the import that brought the data into Hudu.
  • Job: the background job that performed the action.
  • MCP: the user that created or updated the record via the MCP server, shown as the user's name followed by "via MCP" (for example, "Jane Smith via MCP").
  • Hudini Agent Run Job: the job that created or updated the record while Hudini was completing a user's request.

This makes it easier to trace exactly where a change came from, audit automation and AI activity, and troubleshoot unexpected updates to your documentation.

    Give each API key a clear, descriptive name (for example, the script or tool that uses it) so its activity is easy to identify in your logs. API key names must be unique.

Additional abilities

Filtering activity logs by resource type via the API

The activity logs API endpoint supports filtering by resource type, allowing developers to retrieve activity for a specific kind of record (such as assets, passwords, or articles) without pulling the full log.

    Visit REST API for additional information on using the Hudu API. The full endpoint reference, including available filter parameters, can be found in your Hudu instance under the Hudu admin area >> Account Administration >> API Keys >> View the API Documentation.

FAQ

Can activity log entries be edited or deleted?

No. Activity logs are immutable and cannot be modified or deleted by any user or administrator, and all log data is retained indefinitely.

Why do some older entries still show HuduBot?

Entries recorded before source attribution was introduced in v2.45 keep their original attribution. Because activity logs are immutable, these historical entries are not updated. New entries name the specific API key, integration, import, or job responsible.

How can I tell if a record was created or changed by AI?

Changes made through the Hudu MCP server show the user's name followed by "via MCP." Changes Hudini makes while completing a request show Hudini Agent Run Job. Changes made directly in Hudu show the user's name only.

Are activity logs available for every item in Hudu?

Activity logs are kept for every individual item stored within Hudu, with the exception of processes and expirations.

Was this article helpful?
0 out of 0 found this helpful