Keep one 401 audit per IP+path window, and hide historical unauthorized noise from the default business view.
Co-authored-by: Cursor <cursoragent@cursor.com>
Persist only business events and mutating/failed HTTP calls, and default the audit UI to a business view with an explicit HTTP filter.
Co-authored-by: Cursor <cursoragent@cursor.com>
Make session lifecycle and typed CLI lines searchable in audit_log with password redaction, and surface summaries plus device filters in the ops UI.
Co-authored-by: Cursor <cursoragent@cursor.com>
Add capability RBAC, Alembic bootstrap, optional worker schedulers, and close public docs by default so lab installs stay usable without shared signing keys.
Co-authored-by: Cursor <cursoragent@cursor.com>