Skip to main content
The Policy audit tab under Settings › Workspace › Access records recent changes to your tenant’s MCP permission-group policies. Use it to answer questions like “who changed the FPT Developers policy, and when?” It is a focused view of policy edits — not a catch-all audit of every administrative action.
Policy audit covers MCP permission-group policy changes only. It does not show role grants and revokes, preassignment activity, or impersonation. Those are recorded on a separate identity audit stream (see below), which has no UI.

What the tab shows

The table lists the most recent policy events, capped at the latest 50. Each row has:

The separate identity audit stream

Role grants and revokes, group-mapping create and delete, and impersonation start/end/denied events are emitted to a distinct identity (AUTH) audit stream on the backend. This stream is the authoritative record for those events.
Verify before relying: the identity audit stream has no dedicated UI tab in the product today. To review role, group-mapping, or impersonation events, work with your platform team to query that backend stream. Confirm the current access path before promising it to auditors.

Notes

  • Policy audit records what changed, not runtime tool usage. For “did the user actually call this tool” questions, check your observability backend.
  • The tab shows the latest 50 events; older policy history is not paged in this view.