Every API and MCP call is recorded with the client, the end user or AI agent it acted for, the operation, the resource, and the authorization outcome. Supports investigations, privacy reviews, and continuous monitoring.
Reference design by Iron Brick LLC. Not an official government system; endpoints and data models are adapted to each agency's systems of record during implementation.
Base URLs
https://dev.ironbrick.us/sandbox/audit/v1Iron Brick sandbox (synthetic data; free developer account)https://{agency-gateway}/audit/v1Agency deployment (behind the agency API gateway)
Authentication
Send an OAuth 2.0 bearer token from POST https://dev.ironbrick.us/oauth/token in the Authorization header. Your application must hold the scope listed on each operation. How authentication works.
| Scope | Grants |
|---|---|
audit:read | Read audit events |
GET /audit-events
Query audit events · requires scope audit:read
Parameters
| Name | In | Type | Description |
|---|---|---|---|
actor | query | string | |
actorType | query | string | |
resource | query | string | |
outcome | query | string | |
from required | query | string | |
to | query | string | |
cursor | query | string | Pagination cursor from a previous response. |
limit | query | integer | Maximum items to return. |
Responses
| 200 | A page of audit events |
| 400 | Invalid request |
| 401 | Missing or invalid access token |
| 403 | Caller lacks the required scope |
curl -X GET "https://dev.ironbrick.us/sandbox/audit/v1/audit-events" \
-H "Authorization: Bearer $TOKEN"{
"data": [
{
"auditId": "AUD-9930012",
"occurredAt": "2026-09-30T14:22:05Z",
"clientId": "partner-portal-prod",
"actor": "adjudicator-0442",
"actorType": "ai_agent",
"operation": "cases.getCase",
"resource": "CASE-2026-004817",
"outcome": "allowed",
"requestId": "3f1c9a52-7c1e-4f3e-9d2a-0b8e5f6a1c44"
}
],
"page": {
"nextCursor": "eyJvZmZzZXQiOjUwfQ",
"limit": 50
}
}POST /audit-exports
Export to SIEM or file · requires scope audit:read
Starts an export of audit events in JSON Lines or CEF for Splunk and other SIEM platforms.
Request body application/json
{
"from": "2026-09-01T00:00:00Z",
"to": "2026-09-30T23:59:59Z",
"format": "cef",
"destination": "splunk-hec"
}Responses
| 202 | Export started |
| 400 | Invalid request |
| 401 | Missing or invalid access token |
| 403 | Caller lacks the required scope |
curl -X POST "https://dev.ironbrick.us/sandbox/audit/v1/audit-exports" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"from": "2026-09-01T00:00:00Z", "to": "2026-09-30T23:59:59Z", "format": "cef", "destination": "splunk-hec"}'Schemas
AuditEvent
| Field | Type | Description |
|---|---|---|
auditId | string | |
occurredAt | string (date-time) | |
clientId | string | |
actor | string | End user or agent the call was made for. |
actorType | string (user | system | ai_agent) | |
operation | string | |
resource | string | |
outcome | string (allowed | denied | error) | |
requestId | string (uuid) |