Audit log
Who accessed which server, and when
What gets recorded
Every connection, with a name attached
Connections, not just logins
Every time someone opens a session to a server, it’s logged: who it was, which host, and from which IP address.
Sensitive changes stand out
Exporting the vault, rotating a password, granting or removing a permission: these events are flagged separately so they don’t get lost in routine traffic.
Only the account owner sees it
The full list — showing who on the team connects to what — is an oversight screen for the whole company, not a personal history for each person.
SHTERA’s audit log isn’t a bolted-on add-on: it records the account’s real activity — server connections, vault exports, permission changes, Ansible runs, file explorer and database admin sessions — as it happens, not from a sample or a summary built afterward.
Downloading or deleting a file in the explorer is flagged as sensitive, unlike creating a folder or uploading a file, which are low-risk changes. The idea is that what actually matters doesn’t get lost in the noise.
The list can be filtered by event type, by person and by date range, so answering "did anyone access this server last week" doesn’t depend on anyone’s memory.
The audit log is only available to the account owner: it’s information about the whole team’s activity, not something each person can see about the others.