Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. Track user actions, resource changes, authentication events, and access patterns across accounts, organizations, and projects. Use when asked to audit activity, generate compliance reports, investigate security incidents, review user actions, check change logs, or produce SOC2/GDPR/HIPAA audit evidence. Trigger phrases: audit report, audit trail, compliance audit, user activity log, change log, access audit, security investigation, who changed what, audit events.
72
89%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Generate audit reports and compliance trails using Harness MCP v2 tools.
harness_list with resource_type: "audit_event" -- list audit events with filtersharness_describe with resource_type: "audit_event" -- discover available filters and fieldsAudit events are read-only. You can list and filter them but cannot create, update, or delete them.
harness_describe(resource_type="audit_event")Understand the available filter parameters before querying.
harness_list(
resource_type="audit_event",
org_id="<org>", # optional - scope to organization
project_id="<project>", # optional - scope to project
search_term="<user or resource>", # optional
page=0,
size=100
)Filter results by these standard action types:
| Action | Description |
|---|---|
CREATE | Resource creation |
UPDATE | Resource modification |
DELETE | Resource deletion |
LOGIN | User authentication |
LOGOUT | Session termination |
ACCESS | Resource access |
EXECUTE | Pipeline execution |
Common resource types in audit events:
| Resource Type | Examples |
|---|---|
PIPELINE | Pipeline create, update, delete |
SECRET | Secret access, rotation, deletion |
CONNECTOR | Connector modifications |
SERVICE | Service definition changes |
ENVIRONMENT | Environment configuration changes |
USER | User management actions |
ROLE | Role assignment changes |
USER_GROUP | Group membership changes |
Format findings using the templates in references/report-templates.md.
For report templates (General, User Activity, Security) and compliance framework mappings (SOC 2, GDPR, HIPAA), consult references/report-templates.md.
/audit-report
Generate an audit report for the last 30 days/audit-report
What has john.doe@company.com been doing in the last 7 days?/audit-report
Show all pipeline and environment changes in the production project this month/audit-report
Show all secret access events and privilege changes from last week/audit-report
Generate SOC2 audit evidence for Q4 covering access control and change management| Error | Cause | Solution |
|---|---|---|
| No audit events returned | Time range too narrow or wrong scope | Broaden time range; verify org_id/project_id |
| Access denied | User lacks audit view permissions | Request core_audit_view permission |
| Pagination incomplete | More events than page size | Increment page parameter until all pages fetched |
| Search term returns nothing | User ID format mismatch | Try email, username, and display name variants |
size returned equals the size requested (more pages likely)e554080
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.