# Activity and oversight

Read an owner-scoped record of application decisions.

## Read activity

GET /api/v1/activity requires campaigns:read or an owner session. Use limit and the returned cursor for pagination; an optional campaign_id filters to one campaign. Records include action, resource, actor, timestamp, and safe metadata. No raw agent or provider credential appears in the feed.

The feed records supported application mutations such as campaign creation, status changes, key changes, verified funding/holds, and conversion receipts. It does not capture every read, failed request, or change made directly on the ad network. Reconciliation is the source for current provider status.

## Human oversight

The console exposes real workspace campaigns, approval plans, assigned Meta setup, Creative Studio, keys, funding, results, and activity. Its unauthenticated preview contains sample browser-local data and is labeled as a demo. Agents should read authenticated APIs instead of scraping the preview.

The database makes activity append-only for normal callers. This is an operational audit trail, not an independently notarized log. Share request IDs and resource IDs when investigating an issue; never include secret tokens.

Creative jobs have their own durable records and revision_of links. Read those records for generation status and version lineage; the activity feed is not a complete ledger of every model call. Owners and agents share the same job and variant IDs.