# list_audit_events

Read the platform AUDIT TRAIL (public.audit_log) — the unified who-did-what-when-how ledger across every surface (mcp / busybro / dashboard / rest / db / auth / proxy / daemon / cron / ios / cdp / farm / edge:<fn> — #533: the surface is DERIVED at the DB trigger tier by HOW a write ARRIVED — a direct-Postgres write→db (the tamper class, also flagged by is_direct_pg), a device PostgREST write→ios/cdp/farm/rest by its platform, a dashboard PostgREST write→dashboard, a plain REST write→rest). YOUR OWN events by default (owner-scoped to the calling account's actor_id — the same reach the /audit page gives you), or the WHOLE FLEET with all:true (audit:view operators only; re-verified server-side, fail-closed — for a non-operator all is rejected, never silently widened). Each row is a SLIM projection (no detail/statement_excerpt — fetch those with get_audit_event): id, at, actor_kind (user|service|device|webhook|anon|system), actor_id + actor_label (the human name snapshot), client_id, jti, actor_ip, user_agent, db_session_user, is_direct_pg (a DIRECT-Postgres write — the #026 tamper signature), surface, action, target_kind/target_id/target_label, device_uuid, rows_changed, status (ok|denied|error|timeout), method, latency_ms, request_id (correlate one action across layers). MANDATORY time window: since/until (ISO; since defaults to 24h ago, clamped to ≥ 90 days ago — the retention horizon). Filters: surface, status, actor_id (exact — operators only for a foreign actor), actor_q/action_q/target_q (per-field substring), target_kind+target_id (exact — the history deep-link), request_id, direct_only:true (only direct-PG writes), q (free-text multi-column substring across action/actor/target/surface). KEYSET pagination: pass the returned next_cursor {before_at, before_id} to page further; asc:true for oldest-first; limit (default 100, cap 500). detail is REDACTED at write time (never raw args/secrets). Returns { ok, scope: own|fleet, count, next_cursor, events:[…] }.

Agent View of the PolicyLayer registry record for `list_audit_events`. HTML page: https://policylayer.com/tools/dev-busymate-busymate-devtools/list-audit-events

## Facts

- Tool: `list_audit_events`
- Server: Busymate DevTools (`https://mcp.busymate.dev`) — https://policylayer.com/tools/dev-busymate-busymate-devtools.md
- Homepage: https://github.com/serebano/busymate-devtools
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 12
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `q` | string | no | Free-text substring across action/actor_label/target_label/actor_id/target_id/surface/db_session_user. |
| `all` | boolean | no | audit:view operators only — read EVERY actor's events (the fleet trail) instead of just YOUR OWN. |
| `asc` | boolean | no | Oldest-first (default false = newest-first). |
| `limit` | number | no | Max rows (default 100, cap 500). |
| `since` | string | no | ISO timestamp — window start (default 24h ago; clamped to ≥ 90 days ago). |
| `until` | string | no | ISO timestamp — window end (default now). |
| `status` | string | no | Exact status filter (ok\|denied\|error\|timeout). |
| `actor_q` | string | no | Substring match on actor_label or actor_id. |
| `surface` | string | no | Exact surface filter (mcp\|busybro\|dashboard\|rest\|db\|auth\|proxy\|daemon\|cron\|ios\|cdp\|farm\|edge:<fn>). |
| `action_q` | string | no | Substring match on the action (tool name / route / db:op:table). |
| `actor_id` | string | no | Exact actor id (OAuth sub / device uuid / db role). A FOREIGN actor requires audit:view (all:true). |
| `target_q` | string | no | Substring match on target_label/target_id/target_kind. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "list_audit_events",
    "arguments": {}
  }
}
```

## Why list_audit_events is rated Low

This tool retrieves audit trail data without modifying, executing code, deleting, or moving money. It is a pure Read operation. Severity is medium rather than low because audit logs can reveal sensitive operational details, user behavior patterns, and system configuration that could inform further attacks, though the data is scoped to the caller's own events, which mitigates exposure somewhat.

From the tool's own definition: "Tool name is 'list_audit_events' with description stating 'Read the platform AUDIT TRAIL (public.audit_log)' — explicitly a read operation that retrieves audit log data."

Risk signals: High parameter count (18 properties) · Bulk/mass operation — affects multiple targets

## Use case

AI agents call list_audit_events to retrieve information from Busymate DevTools without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Busymate DevTools:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "list_audit_events": {}
  }
}
```

## Other tools on Busymate DevTools (43)

- `share_advisor_finding` — Execute — https://policylayer.com/tools/dev-busymate-busymate-devtools/share-advisor-finding.md
- `summarize_device_traffic` — Execute — https://policylayer.com/tools/dev-busymate-busymate-devtools/summarize-device-traffic.md
- `download_snapshot` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/download-snapshot.md
- `export_har` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/export-har.md
- `get_advisor_finding` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-advisor-finding.md
- `get_audit_event` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-audit-event.md
- `get_block_rules_device` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-block-rules-device.md
- `get_device` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device.md
- `get_device_egress_fail_posture` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-egress-fail-posture.md
- `get_device_egress_status` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-egress-status.md
- `get_device_health` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-health.md
- `get_device_settings` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-settings.md
- `get_device_status` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-status.md
- `get_entry` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-entry.md
- `get_entry_count` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-entry-count.md
- `get_my_account` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-my-account.md
- `get_push_response` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-push-response.md
- `get_service_group` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-service-group.md
- `get_stats` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-stats.md
- `get_status` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-status.md
- `get_subscription` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-subscription.md
- `get_todo` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-todo.md
- `get_usage` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-usage.md
- `get_workspace` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-workspace.md
- `inspect_requests` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/inspect-requests.md
- `list_advisor_findings` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-advisor-findings.md
- `list_breakpoint_events` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-breakpoint-events.md
- `list_device_audit_modes` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-device-audit-modes.md
- `list_device_events` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-device-events.md
- `list_device_service_groups` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-device-service-groups.md
- …and 13 more: https://policylayer.com/tools/dev-busymate-busymate-devtools.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-busymate-busymate-devtools · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dev-busymate-busymate-devtools
