Getting started

activity

orc activity inspects operation history recorded in a Workspace from the terminal. list returns records newest first and can filter by action type, actor type, timestamp range, and project ID. types discovers action types recorded in the Workspace. get inspects one event timestamp, actor, action type, target, and recorded metadata.

Operations target the selected Workspace. Use --workspace to select the target for this invocation. A list without a project filter covers records within that Workspace. Use this to investigate who performed actions such as sending invitations or changing API keys, and when. To inspect run processing progress, see orc logs.

Execution requires CLI authentication and workspace:settings on the target Workspace. The command displays operations to the extent they are recorded in history. There is no common result field indicating success or failure for every operation.

Usage

terminal
orc activity list

Display activity for the selected Workspace.

terminal
orc activity list --action api_key.created

Filter by action type.

terminal
orc activity get <event-id>

Retrieve one event.

terminal
orc activity types

Discover action types recorded in the Workspace.

Filtering and pagination

Action type and actor

--type filters by exact action types such as api_key.created. Separate multiple values with commas to return records matching any specified type. Up to 50 types can be supplied at once. Discover recorded values with orc activity types. --action can also specify one action type. When both are supplied, records must satisfy both conditions. --actor-type is one of user, api_key, service_account, or system. Multiple filter conditions must all match.

terminal
orc activity list --type api_key.created,api_key.revoked --actor-type user

Display API key creation and revocation records performed by users.

Timestamp range

--since returns records at or after the supplied timestamp; --until returns records before it. Supply ISO 8601 with UTC Z or a time zone offset. Either bound can be supplied alone. When both are supplied, --since must precede --until. Relative periods such as 7d and 30d are not accepted.

terminal
orc activity list --since 2026-05-01T00:00:00Z --until 2026-06-01T00:00:00Z

Display operations recorded from May 1 up to, but not including, June 1.

Project

--project-id retrieves records matching the project ID within the selected Workspace. It does not resolve project names or automatically select a project from the working directory. Operations without a recorded project ID are excluded when this filter is present.

terminal
orc activity list --workspace <workspace-id> --project-id <project-id>

Filter by Workspace and project ID.

Page size and continuation

--limit is the maximum records per page. The default is 50; accepted values are integers from 1 to 200. --cursor passes the API next_cursor unchanged. Keep the same Workspace and filters; do not create or decode cursors.

To retrieve all pages, use the shared --page-all option. It outputs one record per line as NDJSON and continues until no next page remains.

terminal
orc activity list --limit 50 --page-all

Retrieve activity page by page and output one record per line.

Subcommands

list

Lists recorded operations in the selected Workspace by creation time, newest first. Events with identical timestamps are ordered by descending ID. Each item includes event ID, Workspace ID, actor type and ID, action type, target type and ID, timestamp, and metadata. Actor and target IDs may be empty depending on the record.

terminal
orc activity list [options]

Unique options

--actor-type

enum: user|api_key|service_account|system

Type: string. Optional.

terminal
orc activity list --actor-type <value>
--action

value

Type: string. Optional.

terminal
orc activity list --action <value>
--project-id

value

Type: string. Optional.

terminal
orc activity list --project-id <value>
--type

Recorded operation types to match (OR). Accepts repeated query parameters or comma-separated values. Combines with action and other filters using AND. Use activity types to discover types recorded in this workspace.; csv

Type: string. Optional.

terminal
orc activity list --type <value>
--since

Inclusive start timestamp in ISO 8601 format, including UTC Z or a timezone offset. Must be earlier than until when both are provided.; max 64 chars

Type: string. Optional.

terminal
orc activity list --since <value>
--until

Exclusive end timestamp in ISO 8601 format, including UTC Z or a timezone offset.; max 64 chars

Type: string. Optional.

terminal
orc activity list --until <value>

Examples

terminal
orc activity list --actor-type user --limit 20

Retrieve user actions only.

types

Returns an alphabetically ordered list of action types actually recorded in the selected Workspace history. This is not a catalog of every possible operation; types absent from history are not included. Empty history returns an empty list. Use this to check values for --type.

terminal
orc activity types [options]

Examples

terminal
orc activity types --json

Display recorded action types as JSON.

get

Provide an event ID found with list to retrieve that record. Retrieval is restricted to the selected Workspace. Both nonexistent events and events belonging to another Workspace return 404.

terminal
orc activity get <id> [options]

Examples

terminal
orc activity get <event-id> --workspace <workspace-id> --json

Retrieve one record with an explicit Workspace.

Examples

Retrieve Workspace records as JSON.

--json or --format json outputs the CLI JSON envelope. JSON records include workspace_id.

terminal
orc activity list --workspace <workspace-id> --json

Retrieve Workspace records as JSON.

Combine a timestamp range with multiple action types.

terminal
orc activity list --type api_key.created,api_key.revoked --since 2026-05-01T00:00:00Z --until 2026-06-01T00:00:00Z

Combine a timestamp range with multiple action types.

Retrieve one page filtered by action type.

terminal
orc activity list --action api_key.revoked --limit 10

Retrieve one page filtered by action type.

Retrieve all pages of filtered activity.

terminal
orc activity list --actor-type api_key --limit 50 --page-all

Retrieve all pages of filtered activity.

Troubleshooting

Authentication or permission error

Authentication and authorization errors exit with code 2. Inspect authentication with orc status. For 403, check the target Workspace and workspace:settings permission. To change Workspaces, explicitly rerun with --workspace <workspace-id>.

Empty list or missing event

Remove --action, --type, --actor-type, timestamp range, and --project-id filters, then run list for the same Workspace. An operation may not have been recorded or may lack a project ID. For a 404 from get, verify the event ID and Workspace in the list.

Invalid cursor

Do not supply a cursor from another API or a modified value. Start again from the first page. Use --page-all to read all records.

Invalid timestamp or type input

Supply timestamps in ISO format with a time zone, and check start/end ordering. Avoid empty values and trailing commas in --type; use values discovered with orc activity types. Types not yet present in history do not appear in that list.

Permissions

Both listing and individual retrieval require workspace:settings on the target Workspace. Records cannot be retrieved without authentication. An event ID belonging to another Workspace does not return that event content.

Global Options

The following global options can be used with orc activity:

For details and examples, see global options.

  • orc logs: Inspect run processing progress and logs.
  • Global options: Shared settings such as JSON output and Workspace selection.