Audit trail
keygrant records each use of a secret locally: keygrant list shows how often
each one was used, and the agent’s list_secrets also shows when it was last
used. With a cloud account, those events are also
uploaded on the next sync so you can see activity across machines in the
console.
What gets recorded
Events are written for exec, denials, grants, set, rm and revoke. What
is uploaded depends on the audit level:
| Level | Uploaded |
|---|---|
off | nothing |
metadata (default) | secret names, the action, the requesting session, and a hash of the command |
full | everything in metadata, plus the full command text |
Values are never recorded at any level.
Change the level
keygrant cloud audit # show the current level
keygrant cloud audit off
keygrant cloud audit full
The level is per device.
Choosing a level
metadata lets you notice unusual use, for example a secret used from a
session you don’t recognize, without uploading what the commands contained.
Commands can include URLs, file paths and hostnames you may not want to store
anywhere, which is why the full text is opt-in.