Audit trail

keygrant records each use of a secret locally: keygrant list shows how often each one was used, and the agent’s list_secrets also shows when it was last used. With a cloud account, those events are also uploaded on the next sync so you can see activity across machines in the console.

What gets recorded

Events are written for exec, denials, grants, set, rm and revoke. What is uploaded depends on the audit level:

LevelUploaded
offnothing
metadata (default)secret names, the action, the requesting session, and a hash of the command
fulleverything in metadata, plus the full command text

Values are never recorded at any level.

Change the level

keygrant cloud audit              # show the current level
keygrant cloud audit off
keygrant cloud audit full

The level is per device.

Choosing a level

metadata lets you notice unusual use, for example a secret used from a session you don’t recognize, without uploading what the commands contained. Commands can include URLs, file paths and hostnames you may not want to store anywhere, which is why the full text is opt-in.