Configuration Audit
Steinkauz AI records selected administrative changes so organization owners and admins can review who changed what and when. This is Configuration Audit. It is separate from Usage, costs, and activity details, which covers inference usage.
This log is configuration change history, not the policy-decision or usage-attempt tables. Exportable decision and usage evidence exists separately; it is not a tamper-evident or WORM ledger.
Where to find Configuration Audit
Open Settings → Configuration Audit (/settings/audit) while the organization you want to review is active in the organization switcher.
Filter the table by domain, event type, and actor. Expand a row to see structured payload detail. Policy Settings pages (Routing, Providers, Title generation, Budgets, API keys, and Organization) also show the five newest events for that domain in the same table, with a link into this page.
| Domain | Typical events |
|---|---|
| Data routing | Matrix and sensitivity edits; blocked sends that fail the routing matrix |
| Inference providers | Provider create, update, and delete (API keys are never stored in the log) |
| Title generation | Title generation policy changes |
| Organization | Invites, member removal, and role changes |
| Budgets | Cap edits |
| API keys | Key create, revoke, and budget-mode changes (prefix only; the secret is never stored) |
Who can view Configuration Audit
Owners and admins can open Configuration Audit. Members cannot.
What Configuration Audit does not include
Configuration Audit is who changed the rules (and related routing blocks / sensitivity events). It is not chat messages, token usage, or tool executions. For those, use Usage & Activity.
Stripe billing portal and plan changes are not recorded here.