Windsurf Audit Logs: Reading the Current Devin API Evidence
Windsurf audit logs now require a terminology check. Cognition's current documentation exposes enterprise audit events through Devin API v3, while legacy Windsurf Enterprise remains an authentication and billing qualifier. The v3 endpoint supports service-user RBAC and time filters. It also supports action filters and cursor pagination, with actor fields in the response. Investigators still need a separate request-policy record for routed AI HTTP calls.