read_organization_audit_log
Read an Organization's append-only audit log: membership, role, invitation, API-key, MCP-grant, ownership, and Workspace-lifecycle changes, newest first.
# MCP tool reference
1 callable tools.
Use tools/call at https://mcp.schedulerzero.com/mcp with the exact tool name and arguments below. The /tools/ paths in this view are documentation identifiers, not HTTP endpoints. Request execution is disabled for this reference.
Inputs are shown for personal API keys (bound) and for OAuth/delegated agents. Output schemas describe MCP structuredContent: native objects pass through; arrays, scalars and null use a data wrapper. Text content retains the native JSON result.
[Connect a client](/mcp/connect) · [Authentication and authorization](/authentication) · [Generated auth guide](/auth.md) · [Download tool catalog](/mcp-catalog.json) · [Agent documentation](/llms.txt)
## read_organization_audit_log
Read an Organization's append-only audit log: membership, role, invitation, API-key, MCP-grant, ownership, and Workspace-lifecycle changes, newest first.
Call to answer who changed access or configuration and when (access reviews, incident questions). Page with nextCursor.
Only the owner and audit:read holders see the whole Organization; a Workspace Admin must name one Workspace they administer. Anyone else gets not found.
Scopes: audit:read
Risk: read; confirmation: none; idempotency: none.
### Input schema (personal API key)
```json
{
"type": "object",
"properties": {
"organizationId": {
"type": "string",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
"format": "uuid"
},
"workspaceId": {
"type": "string",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
"format": "uuid"
},
"cursor": {
"$ref": "#/$defs/OpaqueId"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 200
}
},
"required": [
"organizationId"
],
"patternProperties": {
"^(?!(?:organizationId|workspaceId|cursor|limit)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"type": "string",
"enum": [
"organizationId",
"workspaceId",
"cursor",
"limit"
]
},
"$defs": {
"OpaqueId": {
"type": "string",
"minLength": 1,
"maxLength": 512
}
}
}
```
### Input schema (OAuth / delegated agent)
```json
{
"type": "object",
"properties": {
"organizationId": {
"type": "string",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
"format": "uuid"
},
"workspaceId": {
"type": "string",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
"format": "uuid"
},
"cursor": {
"$ref": "#/$defs/OpaqueId"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 200
}
},
"required": [
"organizationId"
],
"patternProperties": {
"^(?!(?:organizationId|workspaceId|cursor|limit)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"type": "string",
"enum": [
"organizationId",
"workspaceId",
"cursor",
"limit"
]
},
"$defs": {
"OpaqueId": {
"type": "string",
"minLength": 1,
"maxLength": 512
}
}
}
```
### Output schema (structuredContent)
```json
{
"$defs": {
"OpaqueId": {
"type": "string",
"minLength": 1,
"maxLength": 512
},
"UtcDateTimeEncoded": {
"type": "string",
"pattern": "^\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}\\.\\d{3}Z$"
},
"ShortText": {
"type": "string",
"minLength": 1,
"maxLength": 256
},
"Union_": {
"anyOf": [
{
"type": "null"
},
{
"type": "boolean"
},
{
"type": "number"
},
{
"type": "string"
},
{
"type": "array",
"items": {
"$ref": "#/$defs/Union_"
}
},
{
"type": "object",
"additionalProperties": {
"$ref": "#/$defs/Union_"
}
}
]
},
"OrganizationAuditEvent": {
"type": "object",
"properties": {
"id": {
"$ref": "#/$defs/OpaqueId"
},
"occurredAt": {
"$ref": "#/$defs/UtcDateTimeEncoded"
},
"organizationId": {
"type": "string",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
"format": "uuid"
},
"workspaceId": {
"anyOf": [
{
"type": "string",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
"format": "uuid"
},
{
"type": "null"
}
]
},
"actor": {
"type": "object",
"properties": {
"kind": {
"type": "string",
"enum": [
"user",
"api_key",
"agent",
"operator",
"system"
]
},
"id": {
"anyOf": [
{
"$ref": "#/$defs/OpaqueId"
},
{
"type": "null"
}
]
},
"label": {
"$ref": "#/$defs/OpaqueId"
}
},
"required": [
"kind",
"id",
"label"
],
"patternProperties": {
"^(?!(?:kind|id|label)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"type": "string",
"enum": [
"kind",
"id",
"label"
]
}
},
"action": {
"$ref": "#/$defs/ShortText"
},
"targetKind": {
"$ref": "#/$defs/ShortText"
},
"targetId": {
"$ref": "#/$defs/OpaqueId"
},
"before": {
"anyOf": [
{
"$ref": "#/$defs/Union_"
},
{
"type": "null"
}
]
},
"after": {
"anyOf": [
{
"$ref": "#/$defs/Union_"
},
{
"type": "null"
}
]
},
"requestId": {
"anyOf": [
{
"$ref": "#/$defs/OpaqueId"
},
{
"type": "null"
}
]
},
"metadata": {
"$ref": "#/$defs/Union_"
}
},
"required": [
"id",
"occurredAt",
"organizationId",
"workspaceId",
"actor",
"action",
"targetKind",
"targetId",
"before",
"after",
"requestId",
"metadata"
],
"patternProperties": {
"^(?!(?:id|occurredAt|organizationId|workspaceId|actor|action|targetKind|targetId|before|after|requestId|metadata)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"type": "string",
"enum": [
"id",
"occurredAt",
"organizationId",
"workspaceId",
"actor",
"action",
"targetKind",
"targetId",
"before",
"after",
"requestId",
"metadata"
]
}
},
"OrganizationAuditPage": {
"type": "object",
"properties": {
"events": {
"type": "array",
"items": {
"$ref": "#/$defs/OrganizationAuditEvent"
}
},
"nextCursor": {
"anyOf": [
{
"$ref": "#/$defs/OpaqueId"
},
{
"type": "null"
}
]
},
"scope": {
"type": "string",
"enum": [
"organization",
"workspace"
]
}
},
"required": [
"events",
"nextCursor",
"scope"
],
"patternProperties": {
"^(?!(?:events|nextCursor|scope)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"type": "string",
"enum": [
"events",
"nextCursor",
"scope"
]
}
}
},
"type": "object",
"anyOf": [
{
"allOf": [
{
"$ref": "#/$defs/OrganizationAuditPage"
},
{
"type": "object"
}
]
},
{
"type": "object",
"properties": {
"data": {
"allOf": [
{
"$ref": "#/$defs/OrganizationAuditPage"
},
{
"not": {
"type": "object"
}
}
]
}
},
"required": [
"data"
],
"additionalProperties": false
}
]
}
```
### Underlying API operations
- `organizations.listAuditEvents`: `GET /v1/organizations/:organizationId/audit-events`