Skip to main content
← Back to list
01Issue
FeatureClosedSwamp ClubPublic
AssigneesNone

Relationships

#2764 Docs: use-the-audit-timeline should state the permission swamp audit --server needs

Opened by stack72 · 9/30/2026

swamp-club#2757 changes swamp serve so the audit.timeline request (what swamp audit --server sends) needs admin on access:audit, the same as every other audit request. Before, a read grant on models was enough, which let callers see agent command lines naming resources a deny hides from them. content/manual/how-to/use-the-audit-timeline.md does not cover --server. Add a short section: running the timeline against a server needs admin on access:audit, a model read grant is not enough, and an admin restores access for someone who should keep it by granting admin on access:audit (grant file resource access:audit, actions admin).

02Bog Flow
✓OPEN○TRIAGED○IN PROGRESS◉CLOSED

Closed

10/1/2026, 6:02:12 AM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

stack72 commented 10/1/2026, 6:02:12 AM

Documented in swamp-club PR #1274 (https://github.com/swamp-club/swamp-club/pull/1274, merged 8cb2788). use-the-audit-timeline.md has a 'View the timeline on a server' section: admin on access:audit is required, a model read grant is not enough, and a grant-file example and CLI command restore access. authorization.md lists every serve audit request (audit.unsubscribe is the unchecked exception), and operational-commands.md and run-commands-on-a-remote-server.md point to it. The denial and the restore were verified on a live serve.

Sign in to post a ripple.