Governance overview

Some audit data only matters to administrators — the past approval decisions, and the workspace-level activity log that cuts across every feature. The Governance group collects those.

This group is administrator-only. The sidebar hides it for regular users, and opening one of its pages by URL takes a non-admin to an access-denied page.

How to get here

Open the sidebar and expand Audit → Governance. Only administrators see this group.

Pages in this group

  • Approvals — past approval decisions on work sessions, sudo grants, certificate operations, and other gated requests. Shows the reviewer, the outcome, and the justification on record.
  • Activity log — workspace-level events that don’t belong to the Events group: sign-ins, IAM changes, setting updates, resource access.

How this differs from Events

Events answers “what did people do on my servers?” Governance answers “who decided what at the workspace level?”

The two views overlap occasionally. For example, an approval-grant sudo authorization shows up in both — as a Sudo row (the authorization itself) and as an Approvals row (the decision that allowed it).

The two views answer different questions:

  • Events answers “what command actually ran?”
  • Governance answers “who said yes to allowing it?”

For the operational approval queue (requests still waiting for a decision), use Pending approvals under the Execution group in the sidebar. This Governance section is for reviewing decisions that have already been made.

Last updated: