Skip to content

docs: document OCSF actor type_id changes and new event classes - #511

Open
mindymo wants to merge 1 commit into
mainfrom
docs/ocsf-actor-type-changes
Open

docs: document OCSF actor type_id changes and new event classes#511
mindymo wants to merge 1 commit into
mainfrom
docs/ocsf-actor-type-changes

Conversation

@mindymo

@mindymo mindymo commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Documents the upcoming breaking change to actor.user.type_id (admins now log as 2 instead of 1; service/machine identities now log as 4 instead of 99)
  • Documents new additive fields/behavior: actor.user.groups[], unmapped.audience on API Activity (6003) events, and paired events sharing metadata.correlation_uid
  • Documents four new Identity & Access event classes: 3001 (Account Change), 3004 (Entity Management), 3005 (User Access Management), 3006 (Group Management)

Release date is left as [RELEASE DATE] placeholder — needs to be filled in once the engineering rollout date is confirmed, before merge/publish.

Test plan

  • Confirm release date and replace [RELEASE DATE] placeholders
  • Preview page renders correctly (Warning callout, tables)
  • Cross-check field/value names against final engineering implementation before ship

Adds a breaking-change note for the upcoming actor.user.type_id
remap (admin vs. user, service vs. other), plus docs for the new
unmapped.audience field and four new Identity & Access event classes.
@mintlify

mintlify Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
conductorone 🟢 Ready View Preview Aug 27, 2026, 11:54 PM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant