---
updatedAt: 2026-06-01T05:47:14.000Z
agentTools:
  projectIndex: https://developers.smartrecruiters.com/llms.txt
---

# List audit events

The `ADMINISTRATOR` role is required to access the Audit API. Data collected via the Audit API will be retained at least 26 months. When `eventDateAfter` and `eventDateBefore` are not set, by default, the time range is set to the last 7 days. Below is the list of the events that are currently exposed in the API:
* **USER_ACCOUNT_ACTIVATED** - user account has been activated, user can now login to the system
* **USER_ACCOUNT_CREATED** - user account has been created, in order to log in to the system account has to be activated first
* **USER_ACCOUNT_DEACTIVATED** - user account has been deactivated, logging possibility disabled for the user
* **USER_ACCOUNT_UPDATED** - user account has been modified
* **USER_AUTHENTICATION_INVALID_CREDENTIALS** - user authentication failed due to invalid credentials.
Additional context represents the type of the authentication method:
```json
context: {
    authenticationType: "PASSWORD"
}
```
* **USER_AUTHENTICATION_SUCCESS** - user authentication succeeded
Additional context represents the type of the authentication method:
```json
context: {
    authenticationType: "PASSWORD",
    officeName: "string" //Optional
}
```
* **USER_PASSWORD_CHANGED** - user password has been changed
* **USER_PASSWORD_RESET** - user password has been reset
* **USER_ROLE_CHANGED** - user role has been changed,
Additional context represents previous and current role of the user:
```json
context: {
    currentRole: "RESTRICTED",
    previousRole: "STANDARD"
}
```
* **USER_API_KEY_RENEWED** - user api-key has been renewed
* **USER_LOGOUT** - user has been logged out from the platform
Additional context represents the source of the logout:
```json
context: {
    source: 'string'
}
```
* **CREDENTIALS_CREATED** - api-key or OAuth credentials has been renewed
* **CREDENTIALS_CHANGED** - api-key or OAuth credentials has been modified
* **CREDENTIALS_REVOKED** - api-key or OAuth credentials has been modified
Additional context represents credential type:
```json
context: {
    credentialType: "string"
}
```
* **SEARCH** - user performed search
For entityType CANDIDATE additional context represents candidate search event:
```json
context: {
    keyword: [
        "test"
    ],
    jobTitles: [
        "Freelancer",
        "Software Engineer"
    ],
    jobNames: [
        "Java Developer, San Francisco"
    ],
    companies: [
        "SmartRecruiters"
    ],
    schools: [
        "University of Science and Technology"
    ]
```
* **JOB_DELETED** - job was deleted
Additional context represents the deleted job:
```json
context: {
    jobName: "string",
    jobRefNumber: "string"
}
```
* **HIRING_TEAM_MEMBER_ADDED** - a new member was added to the hiring team of the job
Additional context represents the new member:
```json
context: {
    userId: "string",
    roleId: "string",
    roleName: "string"
}
```
* **HIRING_TEAM_MEMBER_REMOVED** - a member was removed from the hiring team of the job
Additional context represents the removed member:
```json
context: {
    userId: "string"
}
```
* **HIRING_TEAM_ROLE_UPDATED** - role of one of the hiring team members was updated
Additional context represents previous and current role of the updated member:
```json
context: {
    userId: "string",
    previousRoleId: "string",
    previousRoleName: "string",
    currentRoleId: "string",
    currentRoleName: "string"
}
```
* **APPROVAL_DELEGATION_FROM_USER_CREATED** - a user created an approval delegation
* **APPROVAL_DELEGATION_FROM_USER_CANCELLED** - a user cancelled an approval delegation
* **APPROVAL_DELEGATION_TO_USER_CREATED** - an approval delegation to a user (a delegate) has been created
* **APPROVAL_DELEGATION_TO_USER_CANCELLED** - an approval delegation to a user (a delegate) has been created

  Additional context represents approval delegation event's details:

  ```json

  context: {
      originalApproverId: "string",
      delegateApproverId: "string",
      startDate: date,
      endDate: date
  }

  ```

* **JOB_APPROVAL_REQUESTED** - a job approval was requested
Additional context represents approval modified event's details:
```json
comment: {
  text: 'string',
  authorId: 'string',
  date: 'string',

}
context: {
    comments: [comment]
}
```
* **JOB_APPROVAL_APPROVED** - a job approval was approved
Additional context represents approval modified event's details:
```json
comment: {
  text: 'string',
  authorId: 'string',
  date: 'string',

}
context: {
    comments: [comment]
}
```
* **JOB_APPROVAL_REJECTED** - a job approval was rejected
Additional context represents approval modified event's details:
```json
comment: {
  text: 'string',
  authorId: 'string',
  date: 'string',

}
context: {
    comments: [comment]
}
```
* **JOB_APPROVAL_ABANDONED** - a job approval was abandoned
Additional context represents approval modified event's details:
```json
comment: {
  text: 'string',
  authorId: 'string',
  date: 'string',

}
context: {
    comments: [comment]
}
```
* **OFFER_APPROVAL_APPROVED** - an offer approval was approved
* **OFFER_APPROVAL_REJECTED** - an offer approval was rejected
* **OFFER_APPROVAL_ABANDONED** - an offer approval was abandoned

  Additional context represents approval event's details.
  `type` is one of the values:
    * sequential - consent of every approver is required, approval requests are sent one by one in a defined order.
    * parallel -  all approvers can approve at the same time.

  `decisionMode` is one of the values:
    * all - consent of every approver is required
    * any - consent of a single approver is enough

```json
decision: {
  decidedOn: integer,
  decision: 'string',
  decidedBy: 'string',
  userId: 'string'
}
context: {
  approvalRequestId: 'string'
  approvers: [decision]
  type: 'string',
  decisionMode: 'string'
}
```
* **JOB_APPROVAL_STEP_APPROVED** - a job approval step was approved by author
* **JOB_APPROVAL_STEP_REJECTED** - a job approval step was rejected by author
Additional context represents approval step modified event's details:
```json
context: {
    approver: 'string'
    comment: 'string'
}
```
* **JOB_APPROVAL_STEP_SKIPPED** - an author skipped approver for a job approval step
* **OFFER_APPROVAL_STEP_APPROVED** - an offer approval step was approved by author
* **OFFER_APPROVAL_STEP_REJECTED** - an offer approval step was rejected by author
* **OFFER_APPROVAL_STEP_SKIPPED** - an author skipped approver for an offer approval step

  Additional context represents approval step modified event's details:

```json
context: {
    approvalRequestId: "string"
    approver: "string",
    reasonId: "string",
    comment: "string"
}
```
* **JOB_APPROVAL_STEP_DELEGATED** - job approval step was delegated to new approver
* **OFFER_APPROVAL_STEP_DELEGATED** - job approval step was delegated to new approver

  Additional context represents approval step delegated event's details:

```json
context: {
    approvalRequestId: "string"
    originalApproverId: "string",
    delegateApproverId: "string"
}
```
* **OFFER_ACCEPTED** - offer was accepted. Returns viaIntegration which is set to true if offer was accepted via third party integration like Docusign
```json
context: {
    viaIntegration: "boolean"
}
```
* **OFFER_DECLINED** - offer was declined. Returns viaIntegration which is set to true if offer was accepted via third party integration like Docusign
```json
context: {
    viaIntegration: "boolean"
}
```
* **CANDIDATE_PERSONAL_DATA_MODIFIED** - Candidate personal data were modified. Only Web Application actions are audited. Event doesn't cover Customer API. Personal data covers:
    * First Name
    * Last Name
    * E-mail
    * Phone
    * Location
    * Phone Number
    * Social Links (Skype Id, Indeed Id, Twitter account, LinkedIn profile, Facebook profile, Websites)
* **CANDIDATE_PROFILE_MODIFIED** - Candidate profile data were modified. Only Web Application actions are audited. Event doesn't cover Customer API and Mobile application.
* **CANDIDATE_DELETED** - Candidate was deleted. The authorType property can be used to distinguish deletion nature. Following values are possible:
    * USER - candidate was deleted by user
    * SYSTEM - candidate was deleted by compliance mechanism (due to retention period end or lack of consent)
    * CANDIDATE - candidate deleted oneself

* **CANDIDATE_PROFILE_OPENED** - Candidate profile was opened by user. Only Web Application actions are audited. Event doesn't cover Customer API and Mobile application.
* **CANDIDATE_EEO_FILLED** - Missing Candidate EEO informations were filled by user.
* **CANDIDATE_PROFILE_UPDATED_DUE_TO_MERGE** - candidate profile updated due to merge.
Additional context with id of duplicated candidate profile:
```json
context: {
    mergedProfileId: "string"
}
```
* **CANDIDATE_DELETED_DUE_TO_MERGE** - candidate profile deleted due to merge.
Additional context with id of master candidate profile:
```json
context: {
    masterProfileId: "string"
}
```
* **CANDIDATE_TAGS_MODIFIED** - candidate tags have been modified. It means that tags have been added, replaced or deleted from the profile.

  The additional context contains the `tags` that are assigned to the candidate after the successful operation.

  ```json

  context: {
      tags: "string"
  }

  ```

* **APPLICATION_PROPERTIES_UPDATED** - application properties updated.
Additional context with id of updated properties:
```json
context: {
    updatedPropertiesIds: "string",
    updatedPropertiesKeys: "string"
}
```
* **APPLICATION_SOURCE_MODIFIED** - community or job application source has been changed.

  The additional context contains the old and new source identifier after the successful operation.

  ```json

  context: {
      previousSource: "string",
      nextSource: "string"
  }

  ```

* **ONBOARDING_STATUS_UPDATED** - onboarding status updated. Please note that for this event, the application ID must be used as the entity_id parameter for the Audit API. The candidate ID will not work in this case.
Additional context with ids of values:
```json
context: {
    fromValueId: "string",
    toValueId: "string"
}
```
* **JOB_APPLICATION_CREATED** - job application created. Currently, we are auditing only actions undertaken by an employee.
Additional context with ids of values:
```json
context: {
    currentStatus: "string"
}
```
* **JOB_APPLICATION_STATE_MODIFIED** - job application state modified. Currently, we are auditing only actions undertaken by an employee or system user.
Additional context with ids of values:
```json
context: {
    currentStatus: "string",
    currentStep: "string", //optional, might not be returned if lack of configured step
    previousStatus: "string",
    previousStep: "string" //optional, might not be returned if lack of configured step
}
```
* **LRSC_CONSENT_GIVEN** - Consent for data exchange within LinkedIn Recruiter System Connect integration was given.
* **OAUTH_APPLICATION_ACCESS_GRANTED** - Access to OAuth application was granted to given user.
Additional context represents grant's details:
```json
context: {
    applicationId: "string",
    applicationName: "string",
    startDate: "date-time",
    endDate: "date-time"
}
```
JOB_PROPERTY_* events audit changes from both Web Application on Job Field Settings page and Configuration API unless otherwise indicated.
* **JOB_PROPERTY_CREATED** - a job property was created.
* **JOB_PROPERTY_ACTIVATED** - a job property was activated.
* **JOB_PROPERTY_DEACTIVATED** - a job property was deactivated.
* **JOB_PROPERTY_UPDATED** - a job property was updated.
Additional context represents current and previous job property:
```json
property: {
  id: "string",
  label: "string",
  category: "string",
  active: boolean,
  visible: boolean,
  required: boolean
}
context: {
    currentProperty: property,
    previousProperty: property
}
```
* **JOB_PROPERTY_UPDATED_VALUES** - _(deprecated)_ will continue to be emitted until March 2027. Use **JOB_PROPERTY_UPDATED_VALUES_PARTITIONED** instead. For big bulk updates, this event might not be emitted. In such cases, only **JOB_PROPERTY_UPDATED_VALUES_PARTITIONED** events will be available. Values in a job property were updated. Only actions from the Web Application (UI) were audited within this event.
Additional context:

 ```json

 value: {
   id: "string",
   label: "string",
   archived: boolean
 }

 context: {
     currentValues: [value],
     previousValues: [value]
 }

 ```

* **JOB_PROPERTY_UPDATED_VALUES_PARTITIONED** - values in a job property were updated. This is the replacement for **JOB_PROPERTY_UPDATED_VALUES**. Only actions from the Web Application (UI) are audited. Every event includes `aggregationId` in context. For small updates, single event is emitted; for high-volume updates the system emits multiple events with partitioned value sets. When multiple events are emitted for one operation, use the same `aggregationId` to merge them into a single logical update.
Additional context:

  ```json

  value: {
    id: "string",
    label: "string",
    archived: boolean
  }

  context: {
      aggregationId: "string",
      currentValues: [value],
      previousValues: [value]
  }

  ```

* **JOB_PROPERTY_UPDATED_VALUE** - a job property value was updated (changed label, (un)archived). Only actions from Configuration API are audited. These actions from UI are audited within JOB_PROPERTY_UPDATED_VALUES (until March 2027) and JOB_PROPERTY_UPDATED_VALUES_PARTITIONED events.
Additional context represents updated current and previous value:
```json
context: {
    currentValue: value,
    previousValue: value
}
```
* **JOB_PROPERTY_ADDED_VALUE** - a value was added to a job property. Only actions from Configuration API are audited. These actions from UI are audited within JOB_PROPERTY_UPDATED_VALUES (until March 2027) and JOB_PROPERTY_UPDATED_VALUES_PARTITIONED events.
Additional context represents added value:
```json
 context: {
    value: [value]
 }
 ```

* **JOB_PROPERTY_ARCHIVED_VALUE** - a job property value was archived. Only actions from Configuration API are audited. These actions from UI are audited within JOB_PROPERTY_UPDATED_VALUES (until March 2027) and JOB_PROPERTY_UPDATED_VALUES_PARTITIONED events.
Additional context represents archived value id:
```json
context: {
    valueId: "string"
}
```
* **JOB_PROPERTY_DEPENDENT_PROPERTIES_UPDATED** - job property dependents were updated.
Additional context represents updated dependent properties:
```json
context: {
    currentDependents: ["string"],
    previousDependents: ["string"]
}
```
* **JOB_PROPERTY_DEPENDENT_VALUES_UPDATED** - job property dependent values were updated.
Additional context represents added or updated dependent values:
```json
dependentValue: {
  "parent": {
    "id": "string",
    "label": "string"
  },
  "values": [value],
  "valuesIds": ["string"]
}

context: {
    dependentId: "string",
    currentDependentValues: [dependentValue],
    previousDependentValues: [dependentValue]
}
```
* **JOB_PROPERTY_DEPENDENT_VALUES_MODIFIED** - job property dependent values were modified
Additional context represents modified dependent values:

 ```json

context: {
  dependentId: "string",
  modifications: {
    "valuesSet": {
      "string": ["string"]
    },
     "valuesAppended": {
       "string": ["string"]
     },
     "valuesRemoved": {
      "string": ["string"]
    },
     "parentValuesWithAllValuesSet": ["string"],
     "clearedOtherParentValues": boolean
  },
}
```

* **JOB_PROPERTIES_CHANGED** - job details has changed (job fields edited on job)
```json
fieldValue: {
  "fieldId": "string",
  "value": "string"
}
context: {
  "previousProperties": [fieldValue],
  "currentProperties": [fieldValue]
}
```
* **POSITION_UPDATED** - when position is updated
* **POSITION_DELETED** - when position is deleted
* **POSITION_CREATED** - when position is created
* **POSITION_ASSIGNED** - when position is assigned
* **CANCEL_NOT_FILLED_POSITION** - when not filled position is cancelled
```json
position: {
  id: 'string',
  positionId: 'string',
  status: 'string',
  openDate: 'date',
  targetStartDate: 'date',
  type: 'string'
}
context: {
  previous: position,
  current: position
}
```
* **JOB_AD_CREATED** - when job ad is created
```json
location: {
  country: 'string'
  countryCode: 'string'
  regionCode: 'string'
  region: 'string'
  city: 'string'
  address: 'string'
  postalCode: 'string'
  longitude: 'string'
  latitude: 'string'
  manual: boolean
}
compensation: {
  currency: 'string',
  min: 'number',
  max: 'number',
  period: 'string'
}
jobAd: {
  id: 'string',
  title: 'string',
  visibility: 'string',
  creatorId: 'string',
  modifierId: 'string',
  createDate: 'string',
  location: location,
  sections: 'string',
  languageId: 'string',
  applyUrl: 'string'
  compensation: compensation
}
context: {
  jobAd: jobAd
}
```
* **JOB_AD_UPDATED** - when job ad is updated
```json

  context: {
    previous: jobAd,
    current: jobAd
  }

```
* **JOB_AD_DELETED** - when job ad is deleted
```json

  context: {
    jobAdId: 'string',
    employeeId: 'string'
  }

```
* **ONBOARDING_PROCESS_DELETED** - when an Onboarding Process is deleted from SmartOnboard
```json

  context: {
    deletionReason: 'string'
  }

```
* **CUSTOMER_REPORT_DOWNLOADED** - when a report is downloaded Additional context with ids of values:
```json

  context: {
      reportFileId: 'string',
      reportId: 'string'
  }

```
* **COMPANY_HIRING_TEAM_ROLE_CREATED** - a new hiring team role was created
Additional context represents the new hiring team role:
```json
context: {
    id: 'string',
    name: 'string',
    active: boolean,
    defaultRole: boolean,
    jobAccessConfiguration: object,
    applicationAccessConfiguration: object
}
```
* **COMPANY_HIRING_TEAM_ROLE_UPDATED** - a hiring team role was updated
Additional context represents the hiring team role before and after the update:
```json
context: {
    before: {
        id: 'string',
        name: 'string',
        active: boolean,
        defaultRole: boolean,
        jobAccessConfiguration: object,
        applicationAccessConfiguration: object
    },
    after: {
        id: 'string',
        name: 'string',
        active: boolean,
        defaultRole: boolean,
        jobAccessConfiguration: object,
        applicationAccessConfiguration: object
    }
}
```
* **COMPANY_HIRING_TEAM_ROLE_DELETED** - a hiring team role was deleted
Additional context represents the deleted hiring team role:
```json
context: {
    id: 'string',
    name: 'string',
    active: boolean,
    defaultRole: boolean,
    jobAccessConfiguration: object,
    applicationAccessConfiguration: object
}
```
* **COMPANY_HIRING_TEAM_ROLE_ACTIVATION_CHANGED** - a hiring team role was activated or deactivated
Additional context represents the activation status before and after the change:
```json
context: {
    id: 'string',
    before: boolean,
    after: boolean
}
```
* **EMPLOYEE_FLAG_SET** - employee flag was manually set for a candidate
* **EMPLOYEE_FLAG_REMOVED** - employee flag was manually removed from a candidate
* **EMPLOYEE_BADGE_ASSIGNED** - employee badge was assigned to a candidate
* **EMPLOYEE_BADGE_REMOVED** - employee badge was removed from a candidate
* **WEB_SSO_CONFIGURATION_UPDATED** - web sso configuration was updated
Additional context represents web sso configuration settings:
```json
context: {
    previousEnableWebSso: boolean,
    currentEnableWebSso: boolean,
    currentCertificateFingerprint: "string",
    previousCertificateFingerprint: "string",
    currentIdentityProviderUrl: "string",
    previousIdentityProviderUrl: "string",
    currentNameIDFormat: "string",
    previousNameIDFormat: "string",
    currentEnableStrictReplayAttackProtection: boolean,
    previousEnableStrictReplayAttackProtection: boolean
}
```
* **MFA_LOGIN_STEP_STARTED** - an MFA challenge was initiated for the user during login
* **MFA_OTP_GENERATED** - a one-time password was generated and sent to the user
Additional context represents the factor type used:
```json
context: {
    factorType: "EMAIL"
}
```
* **MFA_OTP_LOGIN_SUCCESS** - user successfully verified a one-time password during login
Additional context represents the factor type used:
```json
context: {
    factorType: "EMAIL"
}
```
* **MFA_OTP_LOGIN_FAILED** - user failed to verify a one-time password during login
Additional context represents the factor type used:
```json
context: {
    factorType: "EMAIL"
}
```
* **MFA_OTP_LOGIN_ATTEMPTS_EXCEEDED** - the maximum number of failed OTP verification attempts was reached during login
Additional context represents the factor type used:
```json
context: {
    factorType: "EMAIL"
}
```
* **MFA_RECOVERY_CODES_GENERATED** - new recovery codes were generated for the user
* **MFA_RECOVERY_CODE_LOGIN_SUCCESS** - user successfully verified a recovery code during login
* **MFA_RECOVERY_CODE_LOGIN_FAILED** - user failed to verify a recovery code during login
* **MFA_RECOVERY_CODE_LOGIN_ATTEMPTS_EXCEEDED** - the maximum number of failed recovery code verification attempts was reached during login
* **MFA_AUTH_APP_CONFIGURATION_SETUP_SUCCESS** - user successfully configured an authenticator app
* **MFA_AUTH_APP_CONFIGURATION_SETUP_FAILED** - user failed to configure an authenticator app
* **MFA_AUTH_APP_CONFIGURATION_REMOVED** - user removed their authenticator app configuration
* **MFA_COMPANY_CONFIGURATION_UPDATED** - company-level MFA configuration was updated
Additional context represents the updated configuration:
```json
context: {
    factorType: "EMAIL",
    mode: "ENABLED"
}
```


# OpenAPI definition

````json
{
  "openapi": "3.0.1",
  "info": {
    "version": "1",
    "title": "Audit API",
    "contact": {
      "name": "SmartRecruiters",
      "url": "https://developers.smartrecruiters.com"
    }
  },
  "tags": [
    {
      "name": "audit",
      "description": "Audit API"
    }
  ],
  "paths": {
    "/audit-events": {
      "get": {
        "responses": {
          "200": {
            "description": "A single page of audit events",
            "content": {
              "application/json; charset=utf-8": {
                "schema": {
                  "$ref": "#/components/schemas/Events"
                }
              }
            }
          },
          "403": {
            "description": "Audit events access forbidden. ADMINISTRATOR role is required.",
            "content": {
              "application/json; charset=utf-8": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          }
        },
        "description": "The `ADMINISTRATOR` role is required to access the Audit API. Data collected via the Audit API will be retained at least 26 months. When `eventDateAfter` and `eventDateBefore` are not set, by default, the time range is set to the last 7 days. Below is the list of the events that are currently exposed in the API:\n* **USER_ACCOUNT_ACTIVATED** - user account has been activated, user can now login to the system\n* **USER_ACCOUNT_CREATED** - user account has been created, in order to log in to the system account has to be activated first\n* **USER_ACCOUNT_DEACTIVATED** - user account has been deactivated, logging possibility disabled for the user\n* **USER_ACCOUNT_UPDATED** - user account has been modified\n* **USER_AUTHENTICATION_INVALID_CREDENTIALS** - user authentication failed due to invalid credentials.\nAdditional context represents the type of the authentication method:\n```json\ncontext: {\n    authenticationType: \"PASSWORD\"\n}\n```\n* **USER_AUTHENTICATION_SUCCESS** - user authentication succeeded\nAdditional context represents the type of the authentication method:\n```json\ncontext: {\n    authenticationType: \"PASSWORD\",\n    officeName: \"string\" //Optional\n}\n```\n* **USER_PASSWORD_CHANGED** - user password has been changed\n* **USER_PASSWORD_RESET** - user password has been reset\n* **USER_ROLE_CHANGED** - user role has been changed,\nAdditional context represents previous and current role of the user:\n```json\ncontext: {\n    currentRole: \"RESTRICTED\",\n    previousRole: \"STANDARD\"\n}\n```\n* **USER_API_KEY_RENEWED** - user api-key has been renewed\n* **USER_LOGOUT** - user has been logged out from the platform\nAdditional context represents the source of the logout:\n```json\ncontext: {\n    source: 'string'\n}\n```\n* **CREDENTIALS_CREATED** - api-key or OAuth credentials has been renewed\n* **CREDENTIALS_CHANGED** - api-key or OAuth credentials has been modified\n* **CREDENTIALS_REVOKED** - api-key or OAuth credentials has been modified\nAdditional context represents credential type:\n```json\ncontext: {\n    credentialType: \"string\"\n}\n```\n* **SEARCH** - user performed search\nFor entityType CANDIDATE additional context represents candidate search event:\n```json\ncontext: {\n    keyword: [\n        \"test\"\n    ],\n    jobTitles: [\n        \"Freelancer\",\n        \"Software Engineer\"\n    ],\n    jobNames: [\n        \"Java Developer, San Francisco\"\n    ],\n    companies: [\n        \"SmartRecruiters\"\n    ],\n    schools: [\n        \"University of Science and Technology\"\n    ]\n```\n* **JOB_DELETED** - job was deleted\nAdditional context represents the deleted job:\n```json\ncontext: {\n    jobName: \"string\",\n    jobRefNumber: \"string\"\n}\n```\n* **HIRING_TEAM_MEMBER_ADDED** - a new member was added to the hiring team of the job\nAdditional context represents the new member:\n```json\ncontext: {\n    userId: \"string\",\n    roleId: \"string\",\n    roleName: \"string\"\n}\n```\n* **HIRING_TEAM_MEMBER_REMOVED** - a member was removed from the hiring team of the job\nAdditional context represents the removed member:\n```json\ncontext: {\n    userId: \"string\"\n}\n```\n* **HIRING_TEAM_ROLE_UPDATED** - role of one of the hiring team members was updated\nAdditional context represents previous and current role of the updated member:\n```json\ncontext: {\n    userId: \"string\",\n    previousRoleId: \"string\",\n    previousRoleName: \"string\",\n    currentRoleId: \"string\",\n    currentRoleName: \"string\"\n}\n```\n* **APPROVAL_DELEGATION_FROM_USER_CREATED** - a user created an approval delegation\n* **APPROVAL_DELEGATION_FROM_USER_CANCELLED** - a user cancelled an approval delegation\n* **APPROVAL_DELEGATION_TO_USER_CREATED** - an approval delegation to a user (a delegate) has been created\n* **APPROVAL_DELEGATION_TO_USER_CANCELLED** - an approval delegation to a user (a delegate) has been created\n\n  Additional context represents approval delegation event's details:\n\n  ```json\n\n  context: {\n      originalApproverId: \"string\",\n      delegateApproverId: \"string\",\n      startDate: date,\n      endDate: date\n  }\n\n  ```\n\n* **JOB_APPROVAL_REQUESTED** - a job approval was requested\nAdditional context represents approval modified event's details:\n```json\ncomment: {\n  text: 'string',\n  authorId: 'string',\n  date: 'string',\n\n}\ncontext: {\n    comments: [comment]\n}\n```\n* **JOB_APPROVAL_APPROVED** - a job approval was approved\nAdditional context represents approval modified event's details:\n```json\ncomment: {\n  text: 'string',\n  authorId: 'string',\n  date: 'string',\n\n}\ncontext: {\n    comments: [comment]\n}\n```\n* **JOB_APPROVAL_REJECTED** - a job approval was rejected\nAdditional context represents approval modified event's details:\n```json\ncomment: {\n  text: 'string',\n  authorId: 'string',\n  date: 'string',\n\n}\ncontext: {\n    comments: [comment]\n}\n```\n* **JOB_APPROVAL_ABANDONED** - a job approval was abandoned\nAdditional context represents approval modified event's details:\n```json\ncomment: {\n  text: 'string',\n  authorId: 'string',\n  date: 'string',\n\n}\ncontext: {\n    comments: [comment]\n}\n```\n* **OFFER_APPROVAL_APPROVED** - an offer approval was approved\n* **OFFER_APPROVAL_REJECTED** - an offer approval was rejected\n* **OFFER_APPROVAL_ABANDONED** - an offer approval was abandoned\n\n  Additional context represents approval event's details.\n  `type` is one of the values:\n    * sequential - consent of every approver is required, approval requests are sent one by one in a defined order.\n    * parallel -  all approvers can approve at the same time.\n\n  `decisionMode` is one of the values:\n    * all - consent of every approver is required\n    * any - consent of a single approver is enough\n\n```json\ndecision: {\n  decidedOn: integer,\n  decision: 'string',\n  decidedBy: 'string',\n  userId: 'string'\n}\ncontext: {\n  approvalRequestId: 'string'\n  approvers: [decision]\n  type: 'string',\n  decisionMode: 'string'\n}\n```\n* **JOB_APPROVAL_STEP_APPROVED** - a job approval step was approved by author\n* **JOB_APPROVAL_STEP_REJECTED** - a job approval step was rejected by author\nAdditional context represents approval step modified event's details:\n```json\ncontext: {\n    approver: 'string'\n    comment: 'string'\n}\n```\n* **JOB_APPROVAL_STEP_SKIPPED** - an author skipped approver for a job approval step\n* **OFFER_APPROVAL_STEP_APPROVED** - an offer approval step was approved by author\n* **OFFER_APPROVAL_STEP_REJECTED** - an offer approval step was rejected by author\n* **OFFER_APPROVAL_STEP_SKIPPED** - an author skipped approver for an offer approval step\n\n  Additional context represents approval step modified event's details:\n\n```json\ncontext: {\n    approvalRequestId: \"string\"\n    approver: \"string\",\n    reasonId: \"string\",\n    comment: \"string\"\n}\n```\n* **JOB_APPROVAL_STEP_DELEGATED** - job approval step was delegated to new approver\n* **OFFER_APPROVAL_STEP_DELEGATED** - job approval step was delegated to new approver\n\n  Additional context represents approval step delegated event's details:\n\n```json\ncontext: {\n    approvalRequestId: \"string\"\n    originalApproverId: \"string\",\n    delegateApproverId: \"string\"\n}\n```\n* **OFFER_ACCEPTED** - offer was accepted. Returns viaIntegration which is set to true if offer was accepted via third party integration like Docusign\n```json\ncontext: {\n    viaIntegration: \"boolean\"\n}\n```\n* **OFFER_DECLINED** - offer was declined. Returns viaIntegration which is set to true if offer was accepted via third party integration like Docusign\n```json\ncontext: {\n    viaIntegration: \"boolean\"\n}\n```\n* **CANDIDATE_PERSONAL_DATA_MODIFIED** - Candidate personal data were modified. Only Web Application actions are audited. Event doesn't cover Customer API. Personal data covers:\n    * First Name\n    * Last Name\n    * E-mail\n    * Phone\n    * Location\n    * Phone Number\n    * Social Links (Skype Id, Indeed Id, Twitter account, LinkedIn profile, Facebook profile, Websites)\n* **CANDIDATE_PROFILE_MODIFIED** - Candidate profile data were modified. Only Web Application actions are audited. Event doesn't cover Customer API and Mobile application.\n* **CANDIDATE_DELETED** - Candidate was deleted. The authorType property can be used to distinguish deletion nature. Following values are possible:\n    * USER - candidate was deleted by user\n    * SYSTEM - candidate was deleted by compliance mechanism (due to retention period end or lack of consent)\n    * CANDIDATE - candidate deleted oneself\n\n* **CANDIDATE_PROFILE_OPENED** - Candidate profile was opened by user. Only Web Application actions are audited. Event doesn't cover Customer API and Mobile application.\n* **CANDIDATE_EEO_FILLED** - Missing Candidate EEO informations were filled by user.\n* **CANDIDATE_PROFILE_UPDATED_DUE_TO_MERGE** - candidate profile updated due to merge.\nAdditional context with id of duplicated candidate profile:\n```json\ncontext: {\n    mergedProfileId: \"string\"\n}\n```\n* **CANDIDATE_DELETED_DUE_TO_MERGE** - candidate profile deleted due to merge.\nAdditional context with id of master candidate profile:\n```json\ncontext: {\n    masterProfileId: \"string\"\n}\n```\n* **CANDIDATE_TAGS_MODIFIED** - candidate tags have been modified. It means that tags have been added, replaced or deleted from the profile.\n\n  The additional context contains the `tags` that are assigned to the candidate after the successful operation.\n\n  ```json\n\n  context: {\n      tags: \"string\"\n  }\n\n  ```\n\n* **APPLICATION_PROPERTIES_UPDATED** - application properties updated.\nAdditional context with id of updated properties:\n```json\ncontext: {\n    updatedPropertiesIds: \"string\",\n    updatedPropertiesKeys: \"string\"\n}\n```\n* **APPLICATION_SOURCE_MODIFIED** - community or job application source has been changed.\n\n  The additional context contains the old and new source identifier after the successful operation.\n\n  ```json\n\n  context: {\n      previousSource: \"string\",\n      nextSource: \"string\"\n  }\n\n  ```\n\n* **ONBOARDING_STATUS_UPDATED** - onboarding status updated. Please note that for this event, the application ID must be used as the entity_id parameter for the Audit API. The candidate ID will not work in this case.\nAdditional context with ids of values:\n```json\ncontext: {\n    fromValueId: \"string\",\n    toValueId: \"string\"\n}\n```\n* **JOB_APPLICATION_CREATED** - job application created. Currently, we are auditing only actions undertaken by an employee.\nAdditional context with ids of values:\n```json\ncontext: {\n    currentStatus: \"string\"\n}\n```\n* **JOB_APPLICATION_STATE_MODIFIED** - job application state modified. Currently, we are auditing only actions undertaken by an employee or system user.\nAdditional context with ids of values:\n```json\ncontext: {\n    currentStatus: \"string\",\n    currentStep: \"string\", //optional, might not be returned if lack of configured step\n    previousStatus: \"string\",\n    previousStep: \"string\" //optional, might not be returned if lack of configured step\n}\n```\n* **LRSC_CONSENT_GIVEN** - Consent for data exchange within LinkedIn Recruiter System Connect integration was given.\n* **OAUTH_APPLICATION_ACCESS_GRANTED** - Access to OAuth application was granted to given user.\nAdditional context represents grant's details:\n```json\ncontext: {\n    applicationId: \"string\",\n    applicationName: \"string\",\n    startDate: \"date-time\",\n    endDate: \"date-time\"\n}\n```\nJOB_PROPERTY_* events audit changes from both Web Application on Job Field Settings page and Configuration API unless otherwise indicated.\n* **JOB_PROPERTY_CREATED** - a job property was created.\n* **JOB_PROPERTY_ACTIVATED** - a job property was activated.\n* **JOB_PROPERTY_DEACTIVATED** - a job property was deactivated.\n* **JOB_PROPERTY_UPDATED** - a job property was updated.\nAdditional context represents current and previous job property:\n```json\nproperty: {\n  id: \"string\",\n  label: \"string\",\n  category: \"string\",\n  active: boolean,\n  visible: boolean,\n  required: boolean\n}\ncontext: {\n    currentProperty: property,\n    previousProperty: property\n}\n```\n* **JOB_PROPERTY_UPDATED_VALUES** - _(deprecated)_ will continue to be emitted until March 2027. Use **JOB_PROPERTY_UPDATED_VALUES_PARTITIONED** instead. For big bulk updates, this event might not be emitted. In such cases, only **JOB_PROPERTY_UPDATED_VALUES_PARTITIONED** events will be available. Values in a job property were updated. Only actions from the Web Application (UI) were audited within this event.\nAdditional context:\n\n ```json\n\n value: {\n   id: \"string\",\n   label: \"string\",\n   archived: boolean\n }\n\n context: {\n     currentValues: [value],\n     previousValues: [value]\n }\n\n ```\n\n* **JOB_PROPERTY_UPDATED_VALUES_PARTITIONED** - values in a job property were updated. This is the replacement for **JOB_PROPERTY_UPDATED_VALUES**. Only actions from the Web Application (UI) are audited. Every event includes `aggregationId` in context. For small updates, single event is emitted; for high-volume updates the system emits multiple events with partitioned value sets. When multiple events are emitted for one operation, use the same `aggregationId` to merge them into a single logical update.\nAdditional context:\n\n  ```json\n\n  value: {\n    id: \"string\",\n    label: \"string\",\n    archived: boolean\n  }\n\n  context: {\n      aggregationId: \"string\",\n      currentValues: [value],\n      previousValues: [value]\n  }\n\n  ```\n\n* **JOB_PROPERTY_UPDATED_VALUE** - a job property value was updated (changed label, (un)archived). Only actions from Configuration API are audited. These actions from UI are audited within JOB_PROPERTY_UPDATED_VALUES (until March 2027) and JOB_PROPERTY_UPDATED_VALUES_PARTITIONED events.\nAdditional context represents updated current and previous value:\n```json\ncontext: {\n    currentValue: value,\n    previousValue: value\n}\n```\n* **JOB_PROPERTY_ADDED_VALUE** - a value was added to a job property. Only actions from Configuration API are audited. These actions from UI are audited within JOB_PROPERTY_UPDATED_VALUES (until March 2027) and JOB_PROPERTY_UPDATED_VALUES_PARTITIONED events.\nAdditional context represents added value:\n```json\n context: {\n    value: [value]\n }\n ```\n\n* **JOB_PROPERTY_ARCHIVED_VALUE** - a job property value was archived. Only actions from Configuration API are audited. These actions from UI are audited within JOB_PROPERTY_UPDATED_VALUES (until March 2027) and JOB_PROPERTY_UPDATED_VALUES_PARTITIONED events.\nAdditional context represents archived value id:\n```json\ncontext: {\n    valueId: \"string\"\n}\n```\n* **JOB_PROPERTY_DEPENDENT_PROPERTIES_UPDATED** - job property dependents were updated.\nAdditional context represents updated dependent properties:\n```json\ncontext: {\n    currentDependents: [\"string\"],\n    previousDependents: [\"string\"]\n}\n```\n* **JOB_PROPERTY_DEPENDENT_VALUES_UPDATED** - job property dependent values were updated.\nAdditional context represents added or updated dependent values:\n```json\ndependentValue: {\n  \"parent\": {\n    \"id\": \"string\",\n    \"label\": \"string\"\n  },\n  \"values\": [value],\n  \"valuesIds\": [\"string\"]\n}\n\ncontext: {\n    dependentId: \"string\",\n    currentDependentValues: [dependentValue],\n    previousDependentValues: [dependentValue]\n}\n```\n* **JOB_PROPERTY_DEPENDENT_VALUES_MODIFIED** - job property dependent values were modified\nAdditional context represents modified dependent values:\n\n ```json\n\ncontext: {\n  dependentId: \"string\",\n  modifications: {\n    \"valuesSet\": {\n      \"string\": [\"string\"]\n    },\n     \"valuesAppended\": {\n       \"string\": [\"string\"]\n     },\n     \"valuesRemoved\": {\n      \"string\": [\"string\"]\n    },\n     \"parentValuesWithAllValuesSet\": [\"string\"],\n     \"clearedOtherParentValues\": boolean\n  },\n}\n```\n\n* **JOB_PROPERTIES_CHANGED** - job details has changed (job fields edited on job)\n```json\nfieldValue: {\n  \"fieldId\": \"string\",\n  \"value\": \"string\"\n}\ncontext: {\n  \"previousProperties\": [fieldValue],\n  \"currentProperties\": [fieldValue]\n}\n```\n* **POSITION_UPDATED** - when position is updated\n* **POSITION_DELETED** - when position is deleted\n* **POSITION_CREATED** - when position is created\n* **POSITION_ASSIGNED** - when position is assigned\n* **CANCEL_NOT_FILLED_POSITION** - when not filled position is cancelled\n```json\nposition: {\n  id: 'string',\n  positionId: 'string',\n  status: 'string',\n  openDate: 'date',\n  targetStartDate: 'date',\n  type: 'string'\n}\ncontext: {\n  previous: position,\n  current: position\n}\n```\n* **JOB_AD_CREATED** - when job ad is created\n```json\nlocation: {\n  country: 'string'\n  countryCode: 'string'\n  regionCode: 'string'\n  region: 'string'\n  city: 'string'\n  address: 'string'\n  postalCode: 'string'\n  longitude: 'string'\n  latitude: 'string'\n  manual: boolean\n}\ncompensation: {\n  currency: 'string',\n  min: 'number',\n  max: 'number',\n  period: 'string'\n}\njobAd: {\n  id: 'string',\n  title: 'string',\n  visibility: 'string',\n  creatorId: 'string',\n  modifierId: 'string',\n  createDate: 'string',\n  location: location,\n  sections: 'string',\n  languageId: 'string',\n  applyUrl: 'string'\n  compensation: compensation\n}\ncontext: {\n  jobAd: jobAd\n}\n```\n* **JOB_AD_UPDATED** - when job ad is updated\n```json\n\n  context: {\n    previous: jobAd,\n    current: jobAd\n  }\n\n```\n* **JOB_AD_DELETED** - when job ad is deleted\n```json\n\n  context: {\n    jobAdId: 'string',\n    employeeId: 'string'\n  }\n\n```\n* **ONBOARDING_PROCESS_DELETED** - when an Onboarding Process is deleted from SmartOnboard\n```json\n\n  context: {\n    deletionReason: 'string'\n  }\n\n```\n* **CUSTOMER_REPORT_DOWNLOADED** - when a report is downloaded Additional context with ids of values:\n```json\n\n  context: {\n      reportFileId: 'string',\n      reportId: 'string'\n  }\n\n```\n* **COMPANY_HIRING_TEAM_ROLE_CREATED** - a new hiring team role was created\nAdditional context represents the new hiring team role:\n```json\ncontext: {\n    id: 'string',\n    name: 'string',\n    active: boolean,\n    defaultRole: boolean,\n    jobAccessConfiguration: object,\n    applicationAccessConfiguration: object\n}\n```\n* **COMPANY_HIRING_TEAM_ROLE_UPDATED** - a hiring team role was updated\nAdditional context represents the hiring team role before and after the update:\n```json\ncontext: {\n    before: {\n        id: 'string',\n        name: 'string',\n        active: boolean,\n        defaultRole: boolean,\n        jobAccessConfiguration: object,\n        applicationAccessConfiguration: object\n    },\n    after: {\n        id: 'string',\n        name: 'string',\n        active: boolean,\n        defaultRole: boolean,\n        jobAccessConfiguration: object,\n        applicationAccessConfiguration: object\n    }\n}\n```\n* **COMPANY_HIRING_TEAM_ROLE_DELETED** - a hiring team role was deleted\nAdditional context represents the deleted hiring team role:\n```json\ncontext: {\n    id: 'string',\n    name: 'string',\n    active: boolean,\n    defaultRole: boolean,\n    jobAccessConfiguration: object,\n    applicationAccessConfiguration: object\n}\n```\n* **COMPANY_HIRING_TEAM_ROLE_ACTIVATION_CHANGED** - a hiring team role was activated or deactivated\nAdditional context represents the activation status before and after the change:\n```json\ncontext: {\n    id: 'string',\n    before: boolean,\n    after: boolean\n}\n```\n* **EMPLOYEE_FLAG_SET** - employee flag was manually set for a candidate\n* **EMPLOYEE_FLAG_REMOVED** - employee flag was manually removed from a candidate\n* **EMPLOYEE_BADGE_ASSIGNED** - employee badge was assigned to a candidate\n* **EMPLOYEE_BADGE_REMOVED** - employee badge was removed from a candidate\n* **WEB_SSO_CONFIGURATION_UPDATED** - web sso configuration was updated\nAdditional context represents web sso configuration settings:\n```json\ncontext: {\n    previousEnableWebSso: boolean,\n    currentEnableWebSso: boolean,\n    currentCertificateFingerprint: \"string\",\n    previousCertificateFingerprint: \"string\",\n    currentIdentityProviderUrl: \"string\",\n    previousIdentityProviderUrl: \"string\",\n    currentNameIDFormat: \"string\",\n    previousNameIDFormat: \"string\",\n    currentEnableStrictReplayAttackProtection: boolean,\n    previousEnableStrictReplayAttackProtection: boolean\n}\n```\n* **MFA_LOGIN_STEP_STARTED** - an MFA challenge was initiated for the user during login\n* **MFA_OTP_GENERATED** - a one-time password was generated and sent to the user\nAdditional context represents the factor type used:\n```json\ncontext: {\n    factorType: \"EMAIL\"\n}\n```\n* **MFA_OTP_LOGIN_SUCCESS** - user successfully verified a one-time password during login\nAdditional context represents the factor type used:\n```json\ncontext: {\n    factorType: \"EMAIL\"\n}\n```\n* **MFA_OTP_LOGIN_FAILED** - user failed to verify a one-time password during login\nAdditional context represents the factor type used:\n```json\ncontext: {\n    factorType: \"EMAIL\"\n}\n```\n* **MFA_OTP_LOGIN_ATTEMPTS_EXCEEDED** - the maximum number of failed OTP verification attempts was reached during login\nAdditional context represents the factor type used:\n```json\ncontext: {\n    factorType: \"EMAIL\"\n}\n```\n* **MFA_RECOVERY_CODES_GENERATED** - new recovery codes were generated for the user\n* **MFA_RECOVERY_CODE_LOGIN_SUCCESS** - user successfully verified a recovery code during login\n* **MFA_RECOVERY_CODE_LOGIN_FAILED** - user failed to verify a recovery code during login\n* **MFA_RECOVERY_CODE_LOGIN_ATTEMPTS_EXCEEDED** - the maximum number of failed recovery code verification attempts was reached during login\n* **MFA_AUTH_APP_CONFIGURATION_SETUP_SUCCESS** - user successfully configured an authenticator app\n* **MFA_AUTH_APP_CONFIGURATION_SETUP_FAILED** - user failed to configure an authenticator app\n* **MFA_AUTH_APP_CONFIGURATION_REMOVED** - user removed their authenticator app configuration\n* **MFA_COMPANY_CONFIGURATION_UPDATED** - company-level MFA configuration was updated\nAdditional context represents the updated configuration:\n```json\ncontext: {\n    factorType: \"EMAIL\",\n    mode: \"ENABLED\"\n}\n```\n",
        "tags": [
          "audit"
        ],
        "summary": "List audit events",
        "operationId": "audit.get",
        "security": [
          {
            "key": []
          },
          {
            "oauth": [
              "audit_events_read"
            ]
          }
        ],
        "parameters": [
          {
            "in": "query",
            "description": "ISO8601-formatted time boundaries for the event time, Format: yyyy-MM-ddTHH:mm:ss.SSSZZ (example: 2023-01-21T12:50:02.594Z)",
            "name": "eventDateAfter",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "in": "query",
            "description": "ISO8601-formatted time boundaries for the event time, Format: yyyy-MM-ddTHH:mm:ss.SSSZZ (example: 2023-01-21T12:50:02.594Z)",
            "name": "eventDateBefore",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "in": "query",
            "description": "Name of the event",
            "name": "eventName",
            "explode": true,
            "schema": {
              "type": "array",
              "items": {
                "type": "string",
                "enum": [
                  "USER_ACCOUNT_ACTIVATED",
                  "USER_ACCOUNT_CREATED",
                  "USER_ACCOUNT_DEACTIVATED",
                  "USER_ACCOUNT_UPDATED",
                  "USER_AUTHENTICATION_INVALID_CREDENTIALS",
                  "USER_AUTHENTICATION_SUCCESS",
                  "USER_PASSWORD_CHANGED",
                  "USER_PASSWORD_RESET",
                  "USER_ROLE_CHANGED",
                  "USER_API_KEY_RENEWED",
                  "USER_LOGOUT",
                  "CREDENTIALS_CREATED",
                  "CREDENTIALS_CHANGED",
                  "CREDENTIALS_REVOKED",
                  "SEARCH",
                  "CANDIDATE_PERSONAL_DATA_MODIFIED",
                  "CANDIDATE_PROFILE_MODIFIED",
                  "CANDIDATE_DELETED",
                  "CANDIDATE_PROFILE_OPENED",
                  "CANDIDATE_PROFILE_UPDATED_DUE_TO_MERGE",
                  "CANDIDATE_DELETED_DUE_TO_MERGE",
                  "CANDIDATE_TAGS_MODIFIED",
                  "APPLICATION_PROPERTIES_UPDATED",
                  "APPLICATION_SOURCE_MODIFIED",
                  "ONBOARDING_STATUS_UPDATED",
                  "JOB_APPLICATION_CREATED",
                  "JOB_APPLICATION_STATE_MODIFIED",
                  "JOB_DELETED",
                  "HIRING_TEAM_MEMBER_ADDED",
                  "HIRING_TEAM_MEMBER_REMOVED",
                  "HIRING_TEAM_ROLE_UPDATED",
                  "APPROVAL_DELEGATION_FROM_USER_CREATED",
                  "APPROVAL_DELEGATION_FROM_USER_CANCELLED",
                  "APPROVAL_DELEGATION_TO_USER_CREATED",
                  "APPROVAL_DELEGATION_TO_USER_CANCELLED",
                  "JOB_APPROVAL_REQUESTED",
                  "JOB_APPROVAL_APPROVED",
                  "JOB_APPROVAL_REJECTED",
                  "JOB_APPROVAL_ABANDONED",
                  "JOB_APPROVAL_STEP_APPROVED",
                  "JOB_APPROVAL_STEP_REJECTED",
                  "JOB_APPROVAL_STEP_SKIPPED",
                  "JOB_APPROVAL_STEP_DELEGATED",
                  "OFFER_APPROVAL_APPROVED",
                  "OFFER_APPROVAL_REJECTED",
                  "OFFER_APPROVAL_ABANDONED",
                  "OFFER_APPROVAL_STEP_APPROVED",
                  "OFFER_APPROVAL_STEP_REJECTED",
                  "OFFER_APPROVAL_STEP_SKIPPED",
                  "OFFER_APPROVAL_STEP_DELEGATED",
                  "OFFER_ACCEPTED",
                  "OFFER_DECLINED",
                  "CANDIDATE_EEO_FILLED",
                  "LRSC_CONSENT_GIVEN",
                  "OAUTH_APPLICATION_ACCESS_GRANTED",
                  "JOB_PROPERTY_CREATED",
                  "JOB_PROPERTY_UPDATED",
                  "JOB_PROPERTY_ACTIVATED",
                  "JOB_PROPERTY_DEACTIVATED",
                  "JOB_PROPERTY_UPDATED_VALUES",
                  "JOB_PROPERTY_UPDATED_VALUE",
                  "JOB_PROPERTY_ADDED_VALUE",
                  "JOB_PROPERTY_ARCHIVED_VALUE",
                  "JOB_PROPERTY_DEPENDENT_PROPERTIES_UPDATED",
                  "JOB_PROPERTY_DEPENDENT_VALUES_UPDATED",
                  "JOB_PROPERTY_DEPENDENT_VALUES_MODIFIED",
                  "JOB_PROPERTIES_CHANGED",
                  "POSITION_UPDATED",
                  "POSITION_DELETED",
                  "POSITION_CREATED",
                  "POSITION_ASSIGNED",
                  "CANCEL_NOT_FILLED_POSITION",
                  "JOB_AD_CREATED",
                  "JOB_AD_UPDATED",
                  "JOB_AD_DELETED",
                  "ONBOARDING_PROCESS_DELETED",
                  "CUSTOMER_REPORT_DOWNLOADED",
                  "COMPANY_HIRING_TEAM_ROLE_CREATED",
                  "COMPANY_HIRING_TEAM_ROLE_UPDATED",
                  "COMPANY_HIRING_TEAM_ROLE_DELETED",
                  "COMPANY_HIRING_TEAM_ROLE_ACTIVATION_CHANGED",
                  "EMPLOYEE_FLAG_SET",
                  "EMPLOYEE_FLAG_REMOVED",
                  "EMPLOYEE_BADGE_ASSIGNED",
                  "EMPLOYEE_BADGE_REMOVED",
                  "WEB_SSO_CONFIGURATION_UPDATED",
                  "MFA_AUTH_APP_CONFIGURATION_SETUP_SUCCESS",
                  "MFA_AUTH_APP_CONFIGURATION_REMOVED",
                  "MFA_COMPANY_CONFIGURATION_UPDATED",
                  "MFA_OTP_GENERATED",
                  "MFA_OTP_LOGIN_SUCCESS",
                  "MFA_OTP_LOGIN_FAILED",
                  "MFA_RECOVERY_CODES_GENERATED",
                  "MFA_RECOVERY_CODE_LOGIN_SUCCESS",
                  "MFA_RECOVERY_CODE_LOGIN_FAILED",
                  "MFA_LOGIN_STEP_STARTED",
                  "MFA_OTP_LOGIN_ATTEMPTS_EXCEEDED",
                  "MFA_RECOVERY_CODE_LOGIN_ATTEMPTS_EXCEEDED",
                  "MFA_AUTH_APP_CONFIGURATION_SETUP_FAILED"
                ]
              },
              "default": [
                "USER_ACCOUNT_ACTIVATED",
                "USER_ACCOUNT_CREATED",
                "USER_ACCOUNT_DEACTIVATED",
                "USER_ACCOUNT_UPDATED",
                "USER_AUTHENTICATION_INVALID_CREDENTIALS",
                "USER_AUTHENTICATION_SUCCESS",
                "USER_PASSWORD_CHANGED",
                "USER_PASSWORD_RESET",
                "USER_ROLE_CHANGED",
                "USER_API_KEY_RENEWED",
                "USER_LOGOUT",
                "CREDENTIALS_CREATED",
                "CREDENTIALS_CHANGED",
                "CREDENTIALS_REVOKED",
                "SEARCH",
                "JOB_DELETED",
                "HIRING_TEAM_MEMBER_ADDED",
                "HIRING_TEAM_MEMBER_REMOVED",
                "HIRING_TEAM_ROLE_UPDATED",
                "APPROVAL_DELEGATION_FROM_USER_CREATED",
                "APPROVAL_DELEGATION_FROM_USER_CANCELLED",
                "APPROVAL_DELEGATION_TO_USER_CREATED",
                "APPROVAL_DELEGATION_TO_USER_CANCELLED",
                "JOB_APPROVAL_REQUESTED",
                "JOB_APPROVAL_APPROVED",
                "JOB_APPROVAL_REJECTED",
                "JOB_APPROVAL_ABANDONED",
                "JOB_APPROVAL_STEP_APPROVED",
                "JOB_APPROVAL_STEP_REJECTED",
                "JOB_APPROVAL_STEP_SKIPPED",
                "JOB_APPROVAL_STEP_DELEGATED",
                "OFFER_APPROVAL_APPROVED",
                "OFFER_APPROVAL_REJECTED",
                "OFFER_APPROVAL_ABANDONED",
                "OFFER_APPROVAL_STEP_APPROVED",
                "OFFER_APPROVAL_STEP_REJECTED",
                "OFFER_APPROVAL_STEP_SKIPPED",
                "OFFER_APPROVAL_STEP_DELEGATED",
                "OFFER_ACCEPTED",
                "OFFER_DECLINED",
                "CANDIDATE_PERSONAL_DATA_MODIFIED",
                "CANDIDATE_PROFILE_MODIFIED",
                "CANDIDATE_DELETED",
                "CANDIDATE_PROFILE_OPENED",
                "CANDIDATE_EEO_FILLED",
                "CANDIDATE_PROFILE_UPDATED_DUE_TO_MERGE",
                "CANDIDATE_DELETED_DUE_TO_MERGE",
                "CANDIDATE_TAGS_MODIFIED",
                "APPLICATION_PROPERTIES_UPDATED",
                "APPLICATION_SOURCE_MODIFIED",
                "ONBOARDING_STATUS_UPDATED",
                "JOB_APPLICATION_CREATED",
                "JOB_APPLICATION_STATE_MODIFIED",
                "LRSC_CONSENT_GIVEN",
                "OAUTH_APPLICATION_ACCESS_GRANTED",
                "JOB_PROPERTY_CREATED",
                "JOB_PROPERTY_UPDATED",
                "JOB_PROPERTY_ACTIVATED",
                "JOB_PROPERTY_DEACTIVATED",
                "JOB_PROPERTY_UPDATED_VALUES",
                "JOB_PROPERTY_UPDATED_VALUE",
                "JOB_PROPERTY_ADDED_VALUE",
                "JOB_PROPERTY_ARCHIVED_VALUE",
                "JOB_PROPERTY_DEPENDENT_PROPERTIES_UPDATED",
                "JOB_PROPERTY_DEPENDENT_VALUES_UPDATED",
                "JOB_PROPERTY_DEPENDENT_VALUES_MODIFIED",
                "JOB_PROPERTIES_CHANGED",
                "POSITION_UPDATED",
                "POSITION_DELETED",
                "POSITION_CREATED",
                "POSITION_ASSIGNED",
                "CANCEL_NOT_FILLED_POSITION",
                "JOB_AD_CREATED",
                "JOB_AD_UPDATED",
                "JOB_AD_DELETED",
                "ONBOARDING_PROCESS_DELETED",
                "CUSTOMER_REPORT_DOWNLOADED",
                "COMPANY_HIRING_TEAM_ROLE_CREATED",
                "COMPANY_HIRING_TEAM_ROLE_UPDATED",
                "COMPANY_HIRING_TEAM_ROLE_DELETED",
                "COMPANY_HIRING_TEAM_ROLE_ACTIVATION_CHANGED",
                "EMPLOYEE_FLAG_SET",
                "EMPLOYEE_FLAG_REMOVED",
                "EMPLOYEE_BADGE_ASSIGNED",
                "EMPLOYEE_BADGE_REMOVED",
                "MFA_AUTH_APP_CONFIGURATION_SETUP_SUCCESS",
                "MFA_AUTH_APP_CONFIGURATION_REMOVED",
                "MFA_COMPANY_CONFIGURATION_UPDATED",
                "MFA_OTP_GENERATED",
                "MFA_OTP_LOGIN_SUCCESS",
                "MFA_OTP_LOGIN_FAILED",
                "MFA_RECOVERY_CODES_GENERATED",
                "MFA_RECOVERY_CODE_LOGIN_SUCCESS",
                "MFA_RECOVERY_CODE_LOGIN_FAILED",
                "MFA_LOGIN_STEP_STARTED",
                "MFA_OTP_LOGIN_ATTEMPTS_EXCEEDED",
                "MFA_RECOVERY_CODE_LOGIN_ATTEMPTS_EXCEEDED",
                "MFA_AUTH_APP_CONFIGURATION_SETUP_FAILED"
              ]
            }
          },
          {
            "in": "query",
            "description": "Type of the author who generated the event",
            "name": "authorType",
            "explode": true,
            "schema": {
              "type": "array",
              "items": {
                "type": "string",
                "enum": [
                  "USER",
                  "SUPPORT_USER",
                  "SYSTEM",
                  "CANDIDATE"
                ]
              },
              "default": [
                "USER",
                "SUPPORT_USER",
                "SYSTEM",
                "CANDIDATE"
              ]
            }
          },
          {
            "in": "query",
            "description": "Unique identifier of the author",
            "name": "authorId",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "description": "Type of the entity that the event is related to",
            "name": "entityType",
            "explode": true,
            "schema": {
              "type": "array",
              "items": {
                "type": "string",
                "enum": [
                  "USER",
                  "CANDIDATE",
                  "APPLICATION",
                  "OFFER",
                  "JOB",
                  "COMPANY",
                  "JOB_PROPERTY",
                  "JOB_AD",
                  "CREDENTIAL",
                  "REPORT_FILE",
                  "ONBOARDING_PROCESS",
                  "HIRING_TEAM_ROLE"
                ]
              },
              "default": [
                "USER",
                "CANDIDATE",
                "APPLICATION",
                "OFFER",
                "JOB",
                "COMPANY",
                "JOB_PROPERTY",
                "JOB_AD",
                "CREDENTIAL",
                "REPORT_FILE",
                "ONBOARDING_PROCESS",
                "HIRING_TEAM_ROLE"
              ]
            }
          },
          {
            "in": "query",
            "description": "Unique identifier of the entity that the event is related to",
            "name": "entityId",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "description": "Unique identifier for the next page of events",
            "name": "nextPageId",
            "schema": {
              "type": "string"
            }
          },
          {
            "in": "query",
            "description": "Number of audit events to return. Maximum value is 100.",
            "name": "limit",
            "schema": {
              "type": "integer",
              "minimum": 1,
              "maximum": 100,
              "default": 10
            }
          }
        ]
      }
    }
  },
  "components": {
    "securitySchemes": {
      "key": {
        "type": "apiKey",
        "in": "header",
        "name": "x-smarttoken"
      },
      "oauth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://www.smartrecruiters.com/identity/oauth/allow",
            "tokenUrl": "https://api.smartrecruiters.com/identity/oauth/token",
            "scopes": {
              "audit_events_read": "Access Audit Events"
            }
          }
        }
      }
    },
    "schemas": {
      "Events": {
        "type": "object",
        "properties": {
          "nextPageId": {
            "type": "string",
            "description": "Unique identifier for the next page of events"
          },
          "limit": {
            "type": "integer",
            "description": "Number of audit events that were requested"
          },
          "content": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/Event"
            }
          }
        }
      },
      "EventContext": {
        "type": "object",
        "properties": {
          "aggregationId": {
            "type": "string",
            "description": "Identifies events that belong to the same logical operation. Used to merge partitioned JOB_PROPERTY_UPDATED_VALUES_PARTITIONED events when multiple are emitted."
          },
          "authenticationType": {
            "type": "string",
            "enum": [
              "PASSWORD",
              "API_KEY",
              "WEB_SSO",
              "AUTH_TOKEN",
              "SUPPORT_ACCESS"
            ]
          },
          "currentRole": {
            "$ref": "#/components/schemas/UserRole"
          },
          "previousRole": {
            "$ref": "#/components/schemas/UserRole"
          },
          "officeName": {
            "type": "string"
          },
          "previousEnableWebSso": {
            "type": "boolean"
          },
          "currentEnableWebSso": {
            "type": "boolean"
          },
          "currentCertificateFingerprint": {
            "type": "string"
          },
          "previousCertificateFingerprint": {
            "type": "string"
          },
          "currentIdentityProviderUrl": {
            "type": "string"
          },
          "previousIdentityProviderUrl": {
            "type": "string"
          },
          "currentNameIDFormat": {
            "type": "string"
          },
          "previousNameIDFormat": {
            "type": "string"
          },
          "currentEnableStrictReplayAttackProtection": {
            "type": "boolean"
          },
          "previousEnableStrictReplayAttackProtection": {
            "type": "boolean"
          },
          "factorType": {
            "type": "string",
            "enum": [
              "EMAIL",
              "AUTH_APP"
            ],
            "description": "MFA factor type"
          },
          "mode": {
            "type": "string",
            "enum": [
              "ENABLED",
              "DISABLED"
            ],
            "description": "MFA mode for company configuration"
          }
        }
      },
      "Event": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "description": "Unique identifier of the event"
          },
          "eventName": {
            "type": "string",
            "description": "Name of the event"
          },
          "eventDate": {
            "type": "string",
            "format": "date-time",
            "description": "Timestamp when _the thing_ represented by the event actually happened"
          },
          "authorType": {
            "type": "string",
            "enum": [
              "USER",
              "SUPPORT_USER",
              "SYSTEM"
            ],
            "description": "Type of the author who generated the event"
          },
          "authorId": {
            "type": "string",
            "description": "Unique identifier of the author"
          },
          "entityType": {
            "type": "string",
            "enum": [
              "USER",
              "CANDIDATE",
              "APPLICATION",
              "OFFER",
              "JOB",
              "COMPANY",
              "JOB_PROPERTY",
              "JOB_AD",
              "CREDENTIAL",
              "REPORT_FILE",
              "ONBOARDING_PROCESS",
              "WEB_SSO_CONFIGURATION"
            ],
            "description": "Type of the entity that the event is related to"
          },
          "entityId": {
            "type": "string",
            "description": "Unique identifier of the entity that the event is related to"
          },
          "context": {
            "description": "Additional context of event",
            "allOf": [
              {
                "$ref": "#/components/schemas/EventContext"
              }
            ]
          }
        }
      },
      "ErrorResponse": {
        "type": "object",
        "properties": {
          "message": {
            "type": "string"
          },
          "errors": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      },
      "Error": {
        "type": "object",
        "required": [
          "code"
        ],
        "properties": {
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          }
        }
      },
      "UserRole": {
        "type": "string",
        "enum": [
          "ADMINISTRATOR",
          "EMPLOYEE",
          "EXTENDED",
          "RESTRICTED",
          "STANDARD"
        ]
      }
    }
  },
  "servers": [
    {
      "url": "https://api.smartrecruiters.com/audit-api/v201910"
    }
  ]
}
````