Returns statistics about meta-audit access for a tenant: total access count, top users, top endpoints. Tenant admins can only view their own tenant; platform admins can view any tenant.
topUsers[].username names the ACCOUNTABLE reader, and that changed the meaning of this body without changing its shape. The ranking is served from the pre-aggregated USER dimension, which is keyed by the operating human: a read performed inside an impersonation session is attributed to the operator who performed it, not to the account it ran as. Two operators impersonating one account are therefore two entries here, where they were previously one entry naming a human who performed neither read.
It is still called username because that is what it is - a login identity - and no field was added or removed. A client that read this ranking as "which of my tenant's accounts were used" must read it as "which humans read this tenant's trail", which is the question it was always meant to answer.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||