activity
orc activity inspects operation history recorded in a Workspace from the terminal. list returns records newest first and can filter by action type, actor type, timestamp range, and project ID. types discovers action types recorded in the Workspace. get inspects one event timestamp, actor, action type, target, and recorded metadata.
Operations target the selected Workspace. Use --workspace to select the target for this invocation. A list without a project filter covers records within that Workspace. Use this to investigate who performed actions such as sending invitations or changing API keys, and when. To inspect run processing progress, see orc logs.
Execution requires CLI authentication and workspace:settings on the target Workspace. The command displays operations to the extent they are recorded in history. There is no common result field indicating success or failure for every operation.
Usage
orc activity listDisplay activity for the selected Workspace.
orc activity list --action api_key.createdFilter by action type.
orc activity get <event-id>Retrieve one event.
orc activity typesDiscover action types recorded in the Workspace.
Filtering and pagination
Action type and actor
--type filters by exact action types such as api_key.created. Separate multiple values with commas to return records matching any specified type. Up to 50 types can be supplied at once. Discover recorded values with orc activity types. --action can also specify one action type. When both are supplied, records must satisfy both conditions. --actor-type is one of user, api_key, service_account, or system. Multiple filter conditions must all match.
orc activity list --type api_key.created,api_key.revoked --actor-type userDisplay API key creation and revocation records performed by users.
Timestamp range
--since returns records at or after the supplied timestamp; --until returns records before it. Supply ISO 8601 with UTC Z or a time zone offset. Either bound can be supplied alone. When both are supplied, --since must precede --until. Relative periods such as 7d and 30d are not accepted.
orc activity list --since 2026-05-01T00:00:00Z --until 2026-06-01T00:00:00ZDisplay operations recorded from May 1 up to, but not including, June 1.
Project
--project-id retrieves records matching the project ID within the selected Workspace. It does not resolve project names or automatically select a project from the working directory. Operations without a recorded project ID are excluded when this filter is present.
orc activity list --workspace <workspace-id> --project-id <project-id>Filter by Workspace and project ID.
Page size and continuation
--limit is the maximum records per page. The default is 50; accepted values are integers from 1 to 200. --cursor passes the API next_cursor unchanged. Keep the same Workspace and filters; do not create or decode cursors.
To retrieve all pages, use the shared --page-all option. It outputs one record per line as NDJSON and continues until no next page remains.
orc activity list --limit 50 --page-allRetrieve activity page by page and output one record per line.
Subcommands
list
Lists recorded operations in the selected Workspace by creation time, newest first. Events with identical timestamps are ordered by descending ID. Each item includes event ID, Workspace ID, actor type and ID, action type, target type and ID, timestamp, and metadata. Actor and target IDs may be empty depending on the record.
orc activity list [options]Unique options
--actor-type
enum: user|api_key|service_account|system
Type: string. Optional.
orc activity list --actor-type <value>--action
value
Type: string. Optional.
orc activity list --action <value>--project-id
value
Type: string. Optional.
orc activity list --project-id <value>--type
Recorded operation types to match (OR). Accepts repeated query parameters or comma-separated values. Combines with action and other filters using AND. Use activity types to discover types recorded in this workspace.; csv
Type: string. Optional.
orc activity list --type <value>--since
Inclusive start timestamp in ISO 8601 format, including UTC Z or a timezone offset. Must be earlier than until when both are provided.; max 64 chars
Type: string. Optional.
orc activity list --since <value>--until
Exclusive end timestamp in ISO 8601 format, including UTC Z or a timezone offset.; max 64 chars
Type: string. Optional.
orc activity list --until <value>Examples
orc activity list --actor-type user --limit 20Retrieve user actions only.
types
Returns an alphabetically ordered list of action types actually recorded in the selected Workspace history. This is not a catalog of every possible operation; types absent from history are not included. Empty history returns an empty list. Use this to check values for --type.
orc activity types [options]Examples
orc activity types --jsonDisplay recorded action types as JSON.
get
Provide an event ID found with list to retrieve that record. Retrieval is restricted to the selected Workspace. Both nonexistent events and events belonging to another Workspace return 404.
orc activity get <id> [options]Examples
orc activity get <event-id> --workspace <workspace-id> --jsonRetrieve one record with an explicit Workspace.
Examples
Retrieve Workspace records as JSON.
--json or --format json outputs the CLI JSON envelope. JSON records include workspace_id.
orc activity list --workspace <workspace-id> --jsonRetrieve Workspace records as JSON.
Combine a timestamp range with multiple action types.
orc activity list --type api_key.created,api_key.revoked --since 2026-05-01T00:00:00Z --until 2026-06-01T00:00:00ZCombine a timestamp range with multiple action types.
Retrieve one page filtered by action type.
orc activity list --action api_key.revoked --limit 10Retrieve one page filtered by action type.
Retrieve all pages of filtered activity.
orc activity list --actor-type api_key --limit 50 --page-allRetrieve all pages of filtered activity.
Troubleshooting
Authentication or permission error
Authentication and authorization errors exit with code 2. Inspect authentication with orc status. For 403, check the target Workspace and workspace:settings permission. To change Workspaces, explicitly rerun with --workspace <workspace-id>.
Empty list or missing event
Remove --action, --type, --actor-type, timestamp range, and --project-id filters, then run list for the same Workspace. An operation may not have been recorded or may lack a project ID. For a 404 from get, verify the event ID and Workspace in the list.
Invalid cursor
Do not supply a cursor from another API or a modified value. Start again from the first page. Use --page-all to read all records.
Invalid timestamp or type input
Supply timestamps in ISO format with a time zone, and check start/end ordering. Avoid empty values and trailing commas in --type; use values discovered with orc activity types. Types not yet present in history do not appear in that list.
Permissions
Both listing and individual retrieval require workspace:settings on the target Workspace. Records cannot be retrieved without authentication. An event ID belonging to another Workspace does not return that event content.
Global Options
The following global options can be used with orc activity:
For details and examples, see global options.
orc logs: Inspect run processing progress and logs.- Global options: Shared settings such as JSON output and Workspace selection.