KamoCRM

A change to a member's teams is on the security access log — one SECURITY_SETTING_CHANGE/MEDIUM row per member who joined or left, from the team, the member's profile, a deleted team or creation (KamoCollab CP01 final review I1)

FixSecurityService
Shipped
October 5, 2026 at 10:30 PM UTC
Author
Kamo
Commit
ac06949

A team is a level of the rights waterfall, so joining one is a grant (CP01-T14-1). The department and job-title change on the same Position card writes an access-log row; a team change wrote none. - TeamWriteResult carries the write's membership changes (member, team, title, joined or left). - TeamAudit records one row per member after the commit, naming the teams and who changed them, with the whole change as JSON details. Team-side writes (create, update, PUT members) and a team delete write a row per member added or removed; the member-side PUT writes one; creation with teamIds writes one at the creation's commit, never after a rollback. A rename, a rights or roles edit and a PUT of the current members write none. - AccessLogService.logEvents writes a write's rows in ONE async task, 200 to a transaction, so a team of 500 replaced by 500 others does not overrun the shared executor's 200-task queue. - SecurityEventAudit gains recordEach and a details overload, and no longer throws a refused hand-over at a caller whose change already committed.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing