> ## Documentation Index
> Fetch the complete documentation index at: https://docs.enkryptai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List Compliance Log Files

> The coverage record for one scan: which provider export files it opened and closed, how big each was, which period of messages it held, and how many of those messages were flagged.

This answers *what did we cover*, not *what did we find*. Rows appear as `open` when the scan starts a file and are closed as `done`; `skipped` means the file aged out of the provider's 30-day retention window before it could be downloaded.

Four different clocks appear here and they are not interchangeable: `first_event_at` / `last_event_at` are the provider's message timestamps inside the file, `started_at` / `ended_at` are when the scan worked on it, and `end_time` is when the provider closed the file. Rows are ordered by `end_time`, newest first.

Requires the **governance officer** role on the project your API key belongs to. The organization owner is not exempt — an owner without the role gets `403` — and an individual (non-organization) account cannot hold the role at all.



## OpenAPI

````yaml GET /compliance/list-log-files
openapi: 3.0.0
info:
  title: Enkrypt AI APIs
  version: 2.0.0
servers:
  - url: https://api.enkryptai.com
security:
  - apiKeyAuth: []
tags:
  - name: Guardrails
  - name: Code of Conduct
  - name: Endpoints
  - name: Redteam
    description: >-
      Red Team API: submit red-team / threat-modeling / playground / eval runs,
      then poll run status, records, results and compliance. Also two-phase
      threat modeling (categories + data), dataset retrieval, model health,
      findings and risk mitigation. The previous task-based Red Team API is
      under **Archived**.
  - name: Deployments
  - name: AI Proxy
  - name: Leaderboard
  - name: Archived
  - name: MCP Hub
    description: >-
      MCP Hub vulnerability scanning APIs. Submitting scans (the POST endpoints)
      is open to all authenticated callers. The scan **retrieval** APIs — Get
      Scan Job Status, Get Complete Scan Results, List Scans, and Get MCP Hub
      Scan Statistics (the GET endpoints) — are an **enterprise data-license
      feature**: they require your organization to have MCP Hub API access
      enabled by Enkrypt, otherwise they return `403`. Contact us at
      support@enkryptai.com to enable access.
  - name: MCP Registry Servers
  - name: MCP Gateways
  - name: MCP Playground
  - name: Skill Scanner
    description: >-
      Skill Scanner APIs: submit an agent skill (a directory inside a git
      repository) for security scanning, then read the verdict, the risk level
      and the full report. Scanning is asynchronous — a scan takes roughly 30–90
      seconds, so `POST /skill-hub/scan` returns a `scan_id` you poll.


      You see your organization's scans and nobody else's. The identity comes
      from your API key, never from your request — sending `user_email` is a
      `400`.


      For an organization or project API key, scans are filed under the
      **organization**, so every member sees every scan the organization has
      run, whichever project or member submitted it. For an individual account
      it is simply your own scans. Either way List Skill Scans needs no
      parameter to say who you are.
  - name: Compliance
    description: >-
      Compliance APIs: connect a ChatGPT Enterprise workspace, then keep reading
      its compliance logs and scanning every message through one of your saved
      guardrails.


      Every endpoint here — reads as well as writes — requires the **governance
      officer** role on the project your API key belongs to. The organization
      owner is **not** exempt: an owner who has not been granted the role gets
      `403` like anyone else. An individual (non-organization) account cannot
      hold the role at all, so compliance is an organization-only feature today.


      A scan is addressed by name in the `X-Enkrypt-Scan` header, within the
      project its API key belongs to. Message text is never stored: Get
      Compliance Message fetches it live from the provider, and only while the
      provider still holds it.
paths:
  /compliance/list-log-files:
    get:
      tags:
        - Compliance
      summary: List Compliance Log Files
      description: >-
        The coverage record for one scan: which provider export files it opened
        and closed, how big each was, which period of messages it held, and how
        many of those messages were flagged.


        This answers *what did we cover*, not *what did we find*. Rows appear as
        `open` when the scan starts a file and are closed as `done`; `skipped`
        means the file aged out of the provider's 30-day retention window before
        it could be downloaded.


        Four different clocks appear here and they are not interchangeable:
        `first_event_at` / `last_event_at` are the provider's message timestamps
        inside the file, `started_at` / `ended_at` are when the scan worked on
        it, and `end_time` is when the provider closed the file. Rows are
        ordered by `end_time`, newest first.


        Requires the **governance officer** role on the project your API key
        belongs to. The organization owner is not exempt — an owner without the
        role gets `403` — and an individual (non-organization) account cannot
        hold the role at all.
      operationId: compliance_list_log_files
      parameters:
        - name: X-Enkrypt-Scan
          in: header
          required: true
          schema:
            title: Scan Name
            type: string
            description: >-
              The scan's saved name, within the project your API key belongs to.
              Letters, numbers, spaces and `_ & - . /`; must start and end with
              a letter or a number; at most 64 characters.
            example: ChatGPT Enterprise
        - name: page
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            default: 1
          description: 1-based page number.
        - name: per_page
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            maximum: 200
            default: 50
          description: Rows per page, 1–200.
        - name: status
          in: query
          required: false
          schema:
            type: string
            enum:
              - open
              - done
              - partial
              - skipped
          description: >-
            Only return files in this state. `partial` is a defined value that
            is not written yet, so filtering for it legitimately returns nothing
            rather than an error.
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ComplianceLogFileListResponse'
              examples:
                page:
                  summary: First page
                  value:
                    scan_id: 11111111-2222-3333-4444-555555555555
                    scan_name: ChatGPT Enterprise
                    log_files:
                      - scan_id: 11111111-2222-3333-4444-555555555555
                        log_file_id: file_abc123
                        event_type: CONVERSATION_MESSAGE
                        end_time: '2026-09-23T09:00:00Z'
                        file_size: 4471234
                        first_event_at: '2026-09-23T08:00:00Z'
                        last_event_at: '2026-09-23T08:59:59Z'
                        started_at: '2026-09-23T09:01:00Z'
                        ended_at: '2026-09-23T09:03:12Z'
                        messages_count: 1842
                        flagged_count: 7
                        status: done
                        error: null
                    pagination:
                      page: 1
                      per_page: 50
                      total_count: 1
                      total_pages: 1
                      has_next: false
                      has_previous: false
        '400':
          $ref: '#/components/responses/ComplianceBadRequest'
        '401':
          $ref: '#/components/responses/ComplianceUnauthorized'
        '403':
          $ref: '#/components/responses/ComplianceForbidden'
        '404':
          $ref: '#/components/responses/ComplianceNotFound'
        '500':
          $ref: '#/components/responses/ComplianceServerError'
components:
  schemas:
    ComplianceLogFileListResponse:
      title: ComplianceLogFileListResponse
      type: object
      properties:
        scan_id:
          type: string
          format: uuid
        scan_name:
          type: string
        log_files:
          type: array
          items:
            $ref: '#/components/schemas/ComplianceLogFile'
        pagination:
          $ref: '#/components/schemas/CompliancePagination'
    ComplianceLogFile:
      title: ComplianceLogFile
      type: object
      description: >-
        One provider export file this scan opened. Four distinct clocks appear
        here: `first_event_at` / `last_event_at` are the provider's message
        timestamps inside the file, `started_at` / `ended_at` are when the scan
        worked on it, and `end_time` is when the provider closed it.
      properties:
        scan_id:
          type: string
          format: uuid
        log_file_id:
          type: string
          description: The provider's identifier for the file.
        event_type:
          type: string
          nullable: true
          enum:
            - CONVERSATION_MESSAGE
            - CODEX_LOG
            - APP_LOG
            - CUSTOM_AGENTS_LOG
            - CHATGPT_PLUGIN_SPREADSHEET
            - null
          description: Which service the file covers. Null until known.
        end_time:
          type: string
          format: date-time
          nullable: true
          description: >-
            When the provider closed the file. There is no matching start time —
            the provider does not report one, which is why `first_event_at`
            exists. Rows are ordered by this, newest first.
        file_size:
          type: integer
          nullable: true
          description: Size in bytes, when reported.
        first_event_at:
          type: string
          format: date-time
          nullable: true
          description: The earliest message inside the file. Null until the file is parsed.
        last_event_at:
          type: string
          format: date-time
          nullable: true
          description: The latest message inside the file.
        started_at:
          type: string
          format: date-time
          nullable: true
          description: When the scan opened the file.
        ended_at:
          type: string
          format: date-time
          nullable: true
          description: When the scan finished with it.
        messages_count:
          type: integer
          nullable: true
          description: Messages in the file, counted at close.
        flagged_count:
          type: integer
          nullable: true
          description: How many of those the guardrail flagged.
        status:
          type: string
          enum:
            - open
            - done
            - partial
            - skipped
          description: >-
            `open` while being read, `done` when finished, `skipped` when the
            file aged out of the provider's 30-day retention before it could be
            downloaded. `partial` is defined but not written yet.
        error:
          type: string
          nullable: true
    CompliancePagination:
      title: CompliancePagination
      type: object
      properties:
        page:
          type: integer
        per_page:
          type: integer
        total_count:
          type: integer
        total_pages:
          type: integer
        has_next:
          type: boolean
        has_previous:
          type: boolean
    ComplianceErrorResponse:
      title: ComplianceErrorResponse
      type: object
      description: Error envelope returned by the compliance APIs.
      properties:
        error:
          type: string
          example: Scan not found
    ComplianceGatewayErrorResponse:
      title: ComplianceGatewayErrorResponse
      type: object
      description: >-
        Error envelope returned by the gateway for a request it refuses before
        it reaches the compliance service — an unknown body field, a value
        outside an enum, a malformed scan name, or a failed permission check.
      properties:
        code:
          type: integer
          example: 403
        error:
          type: string
          example: Forbidden
        message:
          type: string
          example: Access Denied
        request_id:
          type: string
        time:
          type: number
  responses:
    ComplianceBadRequest:
      description: >-
        Bad Request — a malformed or non-JSON body, an unknown or unexpected
        field, a value outside an enum, a missing or malformed `X-Enkrypt-Scan`,
        a missing `event_id`, out-of-range paging, an empty update, or an
        attempt to change `provider` / `workspace_id` / `scan_id`.
      content:
        application/json:
          schema:
            oneOf:
              - $ref: '#/components/schemas/ComplianceErrorResponse'
              - $ref: '#/components/schemas/ComplianceGatewayErrorResponse'
    ComplianceUnauthorized:
      description: Unauthorized — missing or invalid `apikey` header.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ComplianceGatewayErrorResponse'
    ComplianceForbidden:
      description: >-
        Forbidden — the caller does not hold the **governance officer** role on
        this project, or the account is an individual (non-organization)
        account, which cannot hold that role. The organization owner is not
        exempt: an owner without the role is refused here too.
      content:
        application/json:
          schema:
            oneOf:
              - $ref: '#/components/schemas/ComplianceErrorResponse'
              - $ref: '#/components/schemas/ComplianceGatewayErrorResponse'
    ComplianceNotFound:
      description: >-
        Not Found — no scan of that name in the project your API key belongs to
        (or, on Get Compliance Message, no record of that `event_id`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ComplianceErrorResponse'
    ComplianceServerError:
      description: Internal Server Error.
      content:
        application/json:
          schema:
            oneOf:
              - $ref: '#/components/schemas/ComplianceErrorResponse'
              - $ref: '#/components/schemas/ComplianceGatewayErrorResponse'
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: apikey

````