admin-audit-log-review
Installation
SKILL.md
Admin Audit Log Review
Use this skill to convert admin audit log, privileged action, security evidence, retention, SIEM, and customer traceability questions into a concrete artifact with owners, gates, metrics, and recovery paths.
Workflow
- Identify admins, privileged actions, enterprise requirements, data/security impact, retention needs, customer visibility, SIEM/export needs, and current logging gaps.
- Read
references/admin-audit-log-patterns.md. - Classify events as identity/admin, role/permission, billing, security, integration/API token, data export/delete, configuration, policy, support access, or system-generated change.
- Define event contract, actor/target/context, retention, integrity controls, customer UI, export/API, alerting, privacy redaction, and support/audit workflow.
- Produce audit-log design, state machine, decision table, event schema, coverage checklist, and rollout/backfill plan.
When not to use
- Do not use for generic advice the base model already handles without this skill's specific artifact contract.