Logs and the audit log
Where 3AM logs, how to search its decisions, and how to prove nothing was altered.
Service logs
3AM logs to standard output:
podman logs --since 1h 3am-coreSecrets never appear in the logs or the audit log: connector settings are stored by reference and shown masked.
The audit log (ledger)
Every step 3AM takes is an event in an append-only, hash-chained log under /var/lib/3am/ledger: signals, checks
with their raw results, decisions and reasons, model calls, approvals with the approver's identity, actions,
outcomes and configuration changes.
Search it in the console's Audit log, or over the API.
Verify it
3am-core ledger-verify /var/lib/3am/ledgerIt prints a JSON report and exits 1 if any event was changed, removed or reordered. Run it weekly, and on a copy
before handing the log to an auditor.
Send events to 3AM
Other systems may add their own events (for example, a change made by hand during an incident) with the ingest
token. See POST /v1/events.