TOK-4: Audit log surfaces secret reads per agent #760
Labels
No labels
area:agents
area:dashboard
area:database
area:design
area:design-review
area:flows
area:infra
area:meta
area:security
area:sessions
area:webhook
area:workdir
security
type:bug
type:chore
type:meta
type:user-story
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
charles/claude-hooks#760
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
As an operator, I want the secrets tab in the dashboard to surface a read-history filter scoped to "tokens used by agent X", so that I can answer "why did agent X authenticate as Y?" without shelling into the SQLite DB.
Acceptance criteria
Surface
Tests
dev-defaultanddev-2; the secrets history filter scoped todev-2returns onlydev-2's reads.Out of scope
References
specs/config-to-db.md§ Story TOK-4.