Loading
Render service account on behalf of human author on Agent artifacts audit events
What does this MR do and why?
When a Duo Agent Platform audit event is triggered via a composite identity session, the event's author is the service account but the human who initiated the session is recorded in humanAuthor. Previously only the service account was shown in the audit events timeline.
This MR fetches humanAuthor from the GraphQL API and renders:
<SA avatar> <SA name> on behalf of <human avatar> <human name>
in the audit events timeline when humanAuthor is present. Both names link to their profiles.
References
- Related to https://gitlab.com/gitlab-org/gitlab/-/work_items/611656
- Backend field added in !249452 (merged)
Screenshots or screen recordings
| Before | After |
|---|---|
![]() |
![]() |
How to set up and validate locally
- Enable the
agent_artifacts_pagefeature flag - Navigate to a group or project's Agent Artifacts page
- Open a session that was triggered via a composite identity (service account acting on behalf of a human)
- Observe the audit events timeline shows both the service account and the human author
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Scott Hampton

