Servers
Activity log
The permanent record of everything done to a server — and an honest list of what it cannot see.
Every server has an activity log. It records what was done, by whom, when, and whether it worked. It cannot be edited or deleted by anyone, including you, and it is kept for 365 days.
This is what makes shared access safe. When four people can restart your web server, "who restarted it at 3 pm?" needs an answer that nobody can quietly change.
Passwords and tokens that appear in commands are masked before anything is stored.
What is recorded
Actions on the tabs — one card each, with success or failure: Services, File manager (including uploads and downloads), Docker, PM2, Nginx, Packages, Users, Scheduled, Disk usage, process kills from Monitor, and log truncations.
Terminal sessions — one card per session listing every command typed, or run by the AI helper, with a timestamp and the exit code.
Chat bot requests — one card per request, linked back to the chat so you can read the whole conversation.
Server settings — when the server was added, when its connection details were changed, when notes were edited, when it was removed.
Outside logins — sign-ins read from the server's own login history during the 15-minute health check. This covers people who logged in without going through DevOps Agent at all.
Filtering
- Who — narrow to one person. The first thing to reach for during an investigation.
- By source — Terminal, Chat, or a particular tab.
- Load older activity pages back through the history.
What it cannot see — read this
An audit log that quietly misses things is worse than no log at all, so here is the honest list. Each of these is marked in the log as a gap rather than being silently absent.
- Direct SSH that bypasses DevOps Agent. If someone connects with their own
terminal, the login appears under Outside logins, but not what they
typed. One-off commands and
scpfile transfers do not appear at all. - Nested shells. After
sudo -iorsu -, commands are inside a different shell and are not captured. - Full-screen programs. What you do inside
vim,mysqlortopis invisible — only the fact that you started them. - Shells other than bash and zsh.
- After the recording hook is switched off deliberately.
In short: the log is complete for work done through DevOps Agent, and honest about the boundary.
Using it
"The site went down at 2 pm." Filter to that time. Was there a restart, an upgrade, a config change? The "Last change 3 min ago · Vaibhav: Restarted nginx" line on the health card is the same data at a glance.
"What did the assistant actually do?" Each chat card links to the chat, and approvals are recorded as approved, auto-approved, declined or blocked — with who approved it.
"Is anyone logging in outside the panel?" Check Outside logins. Sign-ins you cannot account for deserve a look at Users.
Removing a server
Deleting a server keeps its activity history. The remove dialog also lists the
team members who worked on it, as a reminder to check what they may have left
behind on the machine itself: entries in ~/.ssh/authorized_keys, Linux users,
and cron jobs.
Not yet available
Exporting the log to CSV or PDF is not built. On the Team plan, activity export is planned; today you read it on screen.
Permissions
Everyone can read the activity log, including Viewers. Nobody can edit or delete it.
