Enterprise Feature — The audit trail requires an Enterprise license. Free and Pro tiers do not log audit events.
Checksum Chain Integrity
To prevent tampering, CostHQ uses a chained SHA-256 checksum architecture. Each event’s checksum is generated by hashing the payload together with the checksum of the previous event:00...00). If a single record is inserted, modified, or deleted, every subsequent checksum in the chain will be invalidated, making tampering mathematically impossible to hide.
Team Identity
In a multi-user or automated environment, audit logs are most useful when events are tagged with specific identities. You can configure a machine’s team identity so that all subsequent audit events are tagged with that user/role.Setting Identity
Managing Identity
Viewing the Audit Log
You can view the audit log directly from the CLI or via the Command Center dashboard.Event Types
The following events are logged:Verifying Integrity
You can mathematically prove the integrity of the local audit log at any time:SOC2-Compliant Export
For compliance audits, you can export the audit trail in a structured, SOC2-friendly JSON format that includes the chain verification status.json or csv formats: