Skip to content

article

Access Log and Audit History

Review who revealed, shared, or changed secrets, and track saved Watchtower and rotation runs over time.

Accountability is what separates a secrets manager from a shared spreadsheet. StretchVault keeps two complementary records: the access log, which captures sensitive actions as they happen, and the audit history, which stores the results of your saved security reviews.

The access log

The access log records the meaningful, security-relevant actions taken in your organization's vaults. Each entry captures what happened, which item or vault it involved, who did it, and when. Logged actions include:

  • Reveals — every time a secret is decrypted and shown.
  • Grants created — every time an item is shared, and at what scope.
  • Grants revoked — every time sharing is withdrawn.
  • Folder creation — structural changes within a vault.
  • Breach-watch reads — when an exposure scan is run.

Crucially, the log records the event, never the secret. You can see that Dana revealed the Acme CMS login at 2:14 PM without the log ever containing the password itself.

Reviewing the access log

  1. Open the Audit area (access log view).
  2. Optionally filter by vault to focus on one area.
  3. Adjust the limit to see more or fewer recent entries.
  4. Read entries newest-first: action, item/vault, actor, scope, and time.

Audit history: saved security runs

Separately from the event log, StretchVault stores the results of your saved security reviews. When you run a full Watchtower review or generate a rotation plan (not the read-only previews), the outcome is written to audit history as a run you can revisit:

  • Watchtower runs record the security score and full findings at that moment.
  • Rotation runs record the prioritized rotation plan that was produced.

Because each run is timestamped and preserved, you can demonstrate that your posture improved — for example that a vault went from a score of 58 to 91 after a cleanup — which is exactly the evidence auditors and clients ask for.

Reviewing audit history

  1. Open the Audit tab.
  2. Browse saved runs, newest first, with an adjustable limit.
  3. Open a run to see the score and findings captured at that time.
  4. Compare an older run to a recent one to show change over time.

A realistic example

A Meridian Studio client asks, during a quarterly review, "How do we know our credentials are being looked after?" The owner opens Audit and shows three saved Watchtower runs over the quarter: scores of 58, then 74, then 91. Then they open the access log, filter to the client's vault, and show that only two named people revealed those credentials all quarter, each time for a documented reason. The conversation is over in five minutes, backed by records rather than assurances.

Reads vs. saved runs

StretchVault distinguishes look from record. The read-only Watchtower and rotation previews compute the same results without writing an audit run — perfect for a quick glance that shouldn't clutter your history. The full run actions save results deliberately. Use previews for exploration and saved runs when you want the outcome on the record.

Tips

  • Run a saved Watchtower review on a regular cadence so your audit history tells a continuous story, not a sporadic one.
  • During offboarding or an incident, filter the access log by vault to see exactly who touched what.
  • Keep the before-and-after saved runs from any big cleanup — they're the most persuasive security evidence you have.
  • Use the limit control to pull a longer window when you're reviewing a whole quarter.

Troubleshooting

I don't see a reveal I expected. Confirm you're filtered to the right vault and your limit is high enough to include the time window. Reveals are only logged when a secret is actually decrypted, not when metadata is viewed.

A Watchtower run I did isn't in audit history. You likely used the read-only preview, which intentionally saves nothing. Run the full review to record it.

FAQ

Does the log ever contain the secret? No. Logs capture the action and context, never the plaintext value.

Who can view the audit history and access log? Administrators of the organization's vaults. It's designed for the people accountable for governance.

Was this helpful?

Help us improve this article

Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.