> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit

> Optional access logs in the customer account, what a deploy record contains, and what operators can see.

Two different records matter in a review. One is optional access logging inside your AWS account. The other is the record Springwinter keeps of a deploy.

## Access logs in your account

A project's Security tab does nothing until you turn it on.

Enable writes load-balancer access logs to a private bucket in your account, named for the project, and keeps those objects for 14 days. The view of recent requests drops the query string, so a secret passed on a URL is not shown in the list. The chart is client addresses.

Enable also turns on Aurora connection logging and exports it to CloudWatch in your account. A SQL connection line shows the client, the database user, and the database name. It does not show the SQL text.

The bucket is private. Project teardown turns the access logs off, deletes the bucket, and deletes the connection-audit parameter group, including for databases that were already removed.

The customer role needs the load-balancer, S3, and Aurora parameter-group actions for Enable. An older connection stack has to be updated before Enable succeeds. If a required action is missing, nothing is turned on.

## The deploy record

Each deploy is a workflow run. Springwinter keeps the run so you can see what happened: the steps, the attempts, and the result. That record can include the input that started the run. Treat it as operational data, not as a customer-managed audit log in your account.

Structured log lines emitted from those runs omit the workflow input, the workflow context, error bodies, credentials, and AWS responses. An assume-role line can include the role ARN, the region, and a session identifier. It does not include the external ID or the temporary keys.

Request logs drop the `environment` parameter so a save of container variables is not written to the request log. The values still land on the task definition in your account, as described on [Credentials](/security/credentials).

## Operators

Springwinter staff have a separate read-only view of workflow runs, connections, and projects. It is not linked from the product. Only email addresses on an allowlist can open it. Everyone else receives the same response as a missing page. That view is not a place where role secrets, external IDs, or workflow inputs are shown.

## What you can do yourself

* Open the IAM role and read the trust policy and the attached permissions.
* Delete the role, or delete the stack, and confirm a later deploy fails.
* Remove an action and confirm create returns `missing_permissions` and creates nothing.
* Uninstall the GitHub App and confirm a later build cannot clone.
* Turn on the Security tab and read the access logs from the bucket in your account.
* Revoke an API token and confirm the old secret is rejected.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.