// File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details.

import { APIResource } from '../../../core/resource';
import * as ExternalStorageAPI from './external-storage';
import {
  ConversationCursorPage,
  type ConversationCursorPageParams,
  PagePromise,
} from '../../../core/pagination';
import { RequestOptions } from '../../../internal/request-options';

// Recognizable options across SDK runtime versions. Keep this independent of
// private RequestOptions fields so older handwritten runtimes still compile.
const normalizeRequestOptionsForQueryKeys = new Set([
  'method',
  'path',
  'query',
  'body',
  'headers',
  'maxRetries',
  'stream',
  'timeout',
  'httpAgent',
  'fetchOptions',
  'signal',
  'idempotencyKey',
  'defaultBaseURL',
  '__metadata',
  '__binaryRequest',
  '__binaryResponse',
  '__streamClass',
  '__security',
  '__synthesizeEventData',
]);

function normalizeRequestOptionsForQuery(
  value: unknown,
  queryKeys: ReadonlyArray<string>,
  options: RequestOptions | undefined,
):
  | ({
      [K in 'headers' | 'maxRetries' | 'timeout' | 'signal' | 'idempotencyKey' | 'query']?: RequestOptions[K];
    } & {
      [
        K in
          | 'method'
          | 'path'
          | 'body'
          | 'stream'
          | 'httpAgent'
          | 'fetchOptions'
          | 'defaultBaseURL'
          | '__metadata'
          | '__binaryRequest'
          | '__binaryResponse'
          | '__streamClass'
          | '__security'
          | '__synthesizeEventData'
      ]?: never;
    })
  | undefined {
  if (typeof value !== 'object' || value === null) return undefined;
  // Optional never fields can still be explicitly undefined unless consumers
  // enable exactOptionalPropertyTypes. Snapshot data without invoking getters.
  const entries = Object.entries(Object.getOwnPropertyDescriptors(value)).filter(
    ([, descriptor]) => descriptor.enumerable && (!('value' in descriptor) || descriptor.value !== undefined),
  );
  const keys = entries.map(([key]) => key);
  const requestOnly = keys.some(
    (key) => normalizeRequestOptionsForQueryKeys.has(key) && !queryKeys.includes(key),
  );
  if (!requestOnly) return undefined;
  // Declared query fields, including stream, must use the query argument.
  // Mixing them with request-only options is ambiguous and could change the return type.
  if (
    options !== undefined ||
    keys.some((key) => !normalizeRequestOptionsForQueryKeys.has(key) || queryKeys.includes(key))
  ) {
    throw new TypeError('Query parameters and request options must be passed as separate arguments.');
  }
  // The query position must not gain authority to change the request destination
  // or transport. Those overrides require the explicit request options argument.
  if (
    keys.some(
      (key) => !['headers', 'maxRetries', 'timeout', 'signal', 'idempotencyKey', 'query'].includes(key),
    )
  ) {
    throw new TypeError('Pass transport overrides in the explicit request options argument.');
  }
  // Copy only the validated fields. Spreading value would reintroduce undefined
  // transport overrides, and deleting them would mutate the caller's object.
  return Object.fromEntries(
    entries.map(([key, descriptor]) => {
      if ('value' in descriptor) return [key, descriptor.value];
      return [key, descriptor.get ? Reflect.apply(descriptor.get, value, []) : undefined];
    }),
  ) as {
    [K in 'headers' | 'maxRetries' | 'timeout' | 'signal' | 'idempotencyKey' | 'query']?: RequestOptions[K];
  } & {
    [
      K in
        | 'method'
        | 'path'
        | 'body'
        | 'stream'
        | 'httpAgent'
        | 'fetchOptions'
        | 'defaultBaseURL'
        | '__metadata'
        | '__binaryRequest'
        | '__binaryResponse'
        | '__streamClass'
        | '__security'
        | '__synthesizeEventData'
    ]?: never;
  };
}

/**
 * List user actions and configuration changes within this organization.
 */
export class AuditLogs extends APIResource {
  /**
   * List user actions and configuration changes within this organization.
   *
   * @example
   * ```ts
   * // Automatically fetches more pages as needed.
   * for await (const auditLogListResponse of client.admin.organization.auditLogs.list()) {
   *   // ...
   * }
   * ```
   */
  list(
    query?:
      | (AuditLogListParams &
          (
            | {
                [
                  K in
                    | 'method'
                    | 'path'
                    | 'query'
                    | 'body'
                    | 'headers'
                    | 'maxRetries'
                    | 'stream'
                    | 'timeout'
                    | 'httpAgent'
                    | 'fetchOptions'
                    | 'signal'
                    | 'idempotencyKey'
                    | 'defaultBaseURL'
                    | '__metadata'
                    | '__binaryRequest'
                    | '__binaryResponse'
                    | '__streamClass'
                    | '__security'
                    | '__synthesizeEventData'
                ]?: never;
              }
            | null
            | undefined
          ))
      | null
      | undefined,
    options?: RequestOptions,
  ): PagePromise<AuditLogListResponsesPage, AuditLogListResponse>;
  list(
    options?: {
      [K in 'headers' | 'maxRetries' | 'timeout' | 'signal' | 'idempotencyKey' | 'query']?: RequestOptions[K];
    } & {
      [
        K in
          | 'method'
          | 'path'
          | 'body'
          | 'stream'
          | 'httpAgent'
          | 'fetchOptions'
          | 'defaultBaseURL'
          | '__metadata'
          | '__binaryRequest'
          | '__binaryResponse'
          | '__streamClass'
          | '__security'
          | '__synthesizeEventData'
      ]?: never;
    },
  ): PagePromise<AuditLogListResponsesPage, AuditLogListResponse>;
  list(
    query:
      | AuditLogListParams
      | ({
          [
            K in 'headers' | 'maxRetries' | 'timeout' | 'signal' | 'idempotencyKey' | 'query'
          ]?: RequestOptions[K];
        } & {
          [
            K in
              | 'method'
              | 'path'
              | 'body'
              | 'stream'
              | 'httpAgent'
              | 'fetchOptions'
              | 'defaultBaseURL'
              | '__metadata'
              | '__binaryRequest'
              | '__binaryResponse'
              | '__streamClass'
              | '__security'
              | '__synthesizeEventData'
          ]?: never;
        })
      | null
      | undefined = {},
    options?: RequestOptions,
  ): PagePromise<AuditLogListResponsesPage, AuditLogListResponse> {
    const normalizeRequestOptionsForQueryOptions = normalizeRequestOptionsForQuery(
      query,
      [
        'actor_emails',
        'actor_ids',
        'after',
        'before',
        'effective_at',
        'event_types',
        'limit',
        'project_ids',
        'resource_ids',
        'tenant_only',
      ],
      options,
    );
    if (normalizeRequestOptionsForQueryOptions !== undefined) {
      options = normalizeRequestOptionsForQueryOptions;
      query = {};
    }
    query = query as AuditLogListParams | null | undefined;
    return this._client.getAPIList('/organization/audit_logs', ConversationCursorPage<AuditLogListResponse>, {
      query,
      ...options,
      __security: { adminAPIKeyAuth: true },
    });
  }
}

export type AuditLogListResponsesPage = ConversationCursorPage<AuditLogListResponse>;

/**
 * A log of a user action or configuration change within this organization.
 */
export interface AuditLogListResponse {
  /**
   * The ID of this log.
   */
  id: string;

  /**
   * The Unix timestamp (in seconds) of the event.
   */
  effective_at: number;

  /**
   * The event type.
   */
  type:
    | 'api_key.created'
    | 'api_key.updated'
    | 'api_key.deleted'
    | 'certificate.created'
    | 'certificate.updated'
    | 'certificate.deleted'
    | 'certificates.activated'
    | 'certificates.deactivated'
    | 'checkpoint.permission.created'
    | 'checkpoint.permission.deleted'
    | 'external_key.registered'
    | 'external_key.removed'
    | 'external_storage.registered'
    | 'external_storage.removed'
    | 'group.created'
    | 'group.updated'
    | 'group.deleted'
    | 'invite.sent'
    | 'invite.accepted'
    | 'invite.deleted'
    | 'ip_allowlist.created'
    | 'ip_allowlist.updated'
    | 'ip_allowlist.deleted'
    | 'ip_allowlist.config.activated'
    | 'ip_allowlist.config.deactivated'
    | 'login.succeeded'
    | 'login.failed'
    | 'logout.succeeded'
    | 'logout.failed'
    | 'organization.updated'
    | 'project.created'
    | 'project.updated'
    | 'project.archived'
    | 'project.deleted'
    | 'rate_limit.updated'
    | 'rate_limit.deleted'
    | 'resource.deleted'
    | 'tunnel.created'
    | 'tunnel.updated'
    | 'tunnel.deleted'
    | 'workload_identity_provider.created'
    | 'workload_identity_provider.updated'
    | 'workload_identity_provider.deleted'
    | 'workload_identity_provider_mapping.created'
    | 'workload_identity_provider_mapping.updated'
    | 'workload_identity_provider_mapping.deleted'
    | 'role.created'
    | 'role.updated'
    | 'role.deleted'
    | 'role.assignment.created'
    | 'role.assignment.deleted'
    | 'role.bound_to_resource'
    | 'role.unbound_from_resource'
    | 'scim.enabled'
    | 'scim.disabled'
    | 'service_account.created'
    | 'service_account.updated'
    | 'service_account.deleted'
    | 'user.added'
    | 'user.updated'
    | 'user.deleted'
    | 'tenant.metadata.updated'
    | 'tenant.microsoft_entra_mapping.upserted'
    | 'tenant.microsoft_entra_mapping.deleted'
    | 'tenant.workload_identity.provider.created'
    | 'tenant.workload_identity.provider.updated'
    | 'tenant.workload_identity.provider.archived'
    | 'tenant.workload_identity.mapping.created'
    | 'tenant.workload_identity.mapping.updated'
    | 'tenant.workload_identity.mapping.archived'
    | 'tenant.workload_identity.binding.created'
    | 'tenant.workload_identity.principal.provisioned'
    | 'tenant.workload_identity.access_token.issued'
    | 'tenant.admin_api_key.created'
    | 'tenant.admin_api_key.updated'
    | 'tenant.admin_api_key.deleted'
    | 'tenant.project_api_key.created'
    | 'tenant.trusted_access.business_verification.started'
    | 'tenant.trusted_access.application.submitted'
    | 'tenant.chatgpt_access_token.revoked'
    | 'tenant.migration.completed'
    | 'tenant.sso.migrated'
    | 'tenant.domains.migrated'
    | 'tenant.sso_connection.created'
    | 'tenant.sso_connection.updated'
    | 'tenant.sso_connection.deleted'
    | 'tenant.sso_connection.setup.started'
    | 'tenant.policy.created'
    | 'tenant.policy.updated'
    | 'tenant.policy.deleted'
    | 'tenant.policy.attached'
    | 'tenant.policy.detached'
    | 'tenant.principal_authentication_policy.resolved'
    | 'tenant.scim.setup.started'
    | 'tenant.scim.deletion.requested'
    | 'tenant.scim.directory.created'
    | 'tenant.product_access_policy.updated'
    | 'tenant.resource_share_grant.created'
    | 'tenant.resource_share_grant.updated'
    | 'tenant.resource_share_grant.accepted'
    | 'tenant.resource_share_grant.declined'
    | 'tenant.resource_share_grant.revoked'
    | 'tenant.resource_share_grant.deleted'
    | 'tenant.service_account.updated'
    | 'tenant.service_account.deleted'
    | 'tenant.service_account.token.revoked'
    | 'tenant.billing.overage_limit.updated'
    | 'tenant.billing.alerts.updated'
    | 'tenant.billing.info.updated'
    | 'tenant.usage_limit.workspace.updated'
    | 'tenant.usage_limit.group.updated'
    | 'tenant.usage_limit.user.updated'
    | 'tenant.usage_limit.increase_request.updated'
    | 'tenant.usage_limit.increase_request.resolved'
    | 'tenant.group.created'
    | 'tenant.group.updated'
    | 'tenant.group.deleted'
    | 'tenant.group.member.added'
    | 'tenant.group.member.removed'
    | 'tenant.migration_rollout.status.updated'
    | 'tenant.migration_rollout.tier.updated'
    | 'tenant.role.metadata.updated'
    | 'tenant.custom_role.created'
    | 'tenant.custom_role.updated'
    | 'tenant.custom_role.deleted'
    | 'tenant.role_assignment.created'
    | 'tenant.role_assignment.deleted'
    | 'tenant.resource_role_assignment.created'
    | 'tenant.resource_role_assignment.deleted'
    | 'tenant.resource_access.updated'
    | 'tenant.resource_access.deleted'
    | 'tenant.ads_account.onboarding.redemption'
    | 'tenant.session_policy.created'
    | 'tenant.session_policy.updated'
    | 'tenant.session_policy.deleted'
    | 'tenant.session_revocation.started'
    | 'tenant.third_party_app_policy.updated'
    | 'tenant.user.added'
    | 'tenant.user.updated'
    | 'tenant.user.removed'
    | 'tenant.user.looked_up'
    | 'tenant.user.invited'
    | 'tenant.membership.revoked'
    | 'tenant.api_organization_invite.upserted'
    | 'tenant.api_organization_invite.deleted'
    | 'tenant.chatgpt_workspace_invite.upserted'
    | 'tenant.membership.accepted'
    | 'tenant.membership.declined'
    | 'tenant.workspace_invite_email_settings.updated';

  /**
   * The actor who performed the audit logged action.
   */
  actor?: AuditLogListResponse.Actor | null;

  /**
   * The details for events with this `type`.
   */
  'api_key.created'?: AuditLogListResponse.APIKeyCreated;

  /**
   * The details for events with this `type`.
   */
  'api_key.deleted'?: AuditLogListResponse.APIKeyDeleted;

  /**
   * The details for events with this `type`.
   */
  'api_key.updated'?: AuditLogListResponse.APIKeyUpdated;

  /**
   * The details for events with this `type`.
   */
  'certificate.created'?: AuditLogListResponse.CertificateCreated;

  /**
   * The details for events with this `type`.
   */
  'certificate.deleted'?: AuditLogListResponse.CertificateDeleted;

  /**
   * The details for events with this `type`.
   */
  'certificate.updated'?: AuditLogListResponse.CertificateUpdated;

  /**
   * The details for events with this `type`.
   */
  'certificates.activated'?: AuditLogListResponse.CertificatesActivated;

  /**
   * The details for events with this `type`.
   */
  'certificates.deactivated'?: AuditLogListResponse.CertificatesDeactivated;

  /**
   * The project and fine-tuned model checkpoint that the checkpoint permission was
   * created for.
   */
  'checkpoint.permission.created'?: AuditLogListResponse.CheckpointPermissionCreated;

  /**
   * The details for events with this `type`.
   */
  'checkpoint.permission.deleted'?: AuditLogListResponse.CheckpointPermissionDeleted;

  /**
   * The details for events with this `type`.
   */
  'external_key.registered'?: AuditLogListResponse.ExternalKeyRegistered;

  /**
   * The details for events with this `type`.
   */
  'external_key.removed'?: AuditLogListResponse.ExternalKeyRemoved;

  /**
   * The details for events with this `type`.
   */
  'external_storage.registered'?: AuditLogListResponse.ExternalStorageRegistered;

  /**
   * The details for events with this `type`.
   */
  'external_storage.removed'?: AuditLogListResponse.ExternalStorageRemoved;

  /**
   * The details for events with this `type`.
   */
  'group.created'?: AuditLogListResponse.GroupCreated;

  /**
   * The details for events with this `type`.
   */
  'group.deleted'?: AuditLogListResponse.GroupDeleted;

  /**
   * The details for events with this `type`.
   */
  'group.updated'?: AuditLogListResponse.GroupUpdated;

  /**
   * The details for events with this `type`.
   */
  'invite.accepted'?: AuditLogListResponse.InviteAccepted;

  /**
   * The details for events with this `type`.
   */
  'invite.deleted'?: AuditLogListResponse.InviteDeleted;

  /**
   * The details for events with this `type`.
   */
  'invite.sent'?: AuditLogListResponse.InviteSent;

  /**
   * The details for events with this `type`.
   */
  'ip_allowlist.config.activated'?: AuditLogListResponse.IPAllowlistConfigActivated;

  /**
   * The details for events with this `type`.
   */
  'ip_allowlist.config.deactivated'?: AuditLogListResponse.IPAllowlistConfigDeactivated;

  /**
   * The details for events with this `type`.
   */
  'ip_allowlist.created'?: AuditLogListResponse.IPAllowlistCreated;

  /**
   * The details for events with this `type`.
   */
  'ip_allowlist.deleted'?: AuditLogListResponse.IPAllowlistDeleted;

  /**
   * The details for events with this `type`.
   */
  'ip_allowlist.updated'?: AuditLogListResponse.IPAllowlistUpdated;

  /**
   * The details for events with this `type`.
   */
  'login.failed'?: AuditLogListResponse.LoginFailed;

  /**
   * This event has no additional fields beyond the standard audit log attributes.
   */
  'login.succeeded'?: unknown;

  /**
   * The details for events with this `type`.
   */
  'logout.failed'?: AuditLogListResponse.LogoutFailed;

  /**
   * This event has no additional fields beyond the standard audit log attributes.
   */
  'logout.succeeded'?: unknown;

  /**
   * The details for events with this `type`.
   */
  'organization.updated'?: AuditLogListResponse.OrganizationUpdated;

  /**
   * The project that the action was scoped to. Absent for actions not scoped to
   * projects. Note that any admin actions taken via Admin API keys are associated
   * with the default project.
   */
  project?: AuditLogListResponse.Project;

  /**
   * The details for events with this `type`.
   */
  'project.archived'?: AuditLogListResponse.ProjectArchived;

  /**
   * The details for events with this `type`.
   */
  'project.created'?: AuditLogListResponse.ProjectCreated;

  /**
   * The details for events with this `type`.
   */
  'project.deleted'?: AuditLogListResponse.ProjectDeleted;

  /**
   * The details for events with this `type`.
   */
  'project.updated'?: AuditLogListResponse.ProjectUpdated;

  /**
   * The details for events with this `type`.
   */
  'rate_limit.deleted'?: AuditLogListResponse.RateLimitDeleted;

  /**
   * The details for events with this `type`.
   */
  'rate_limit.updated'?: AuditLogListResponse.RateLimitUpdated;

  /**
   * The details for events with this `type`.
   */
  'role.assignment.created'?: AuditLogListResponse.RoleAssignmentCreated;

  /**
   * The details for events with this `type`.
   */
  'role.assignment.deleted'?: AuditLogListResponse.RoleAssignmentDeleted;

  /**
   * The details for events with this `type`.
   */
  'role.bound_to_resource'?: AuditLogListResponse.RoleBoundToResource;

  /**
   * The details for events with this `type`.
   */
  'role.created'?: AuditLogListResponse.RoleCreated;

  /**
   * The details for events with this `type`.
   */
  'role.deleted'?: AuditLogListResponse.RoleDeleted;

  /**
   * The details for events with this `type`.
   */
  'role.unbound_from_resource'?: AuditLogListResponse.RoleUnboundFromResource;

  /**
   * The details for events with this `type`.
   */
  'role.updated'?: AuditLogListResponse.RoleUpdated;

  /**
   * The details for events with this `type`.
   */
  'scim.disabled'?: AuditLogListResponse.ScimDisabled;

  /**
   * The details for events with this `type`.
   */
  'scim.enabled'?: AuditLogListResponse.ScimEnabled;

  /**
   * The details for events with this `type`.
   */
  'service_account.created'?: AuditLogListResponse.ServiceAccountCreated;

  /**
   * The details for events with this `type`.
   */
  'service_account.deleted'?: AuditLogListResponse.ServiceAccountDeleted;

  /**
   * The details for events with this `type`.
   */
  'service_account.updated'?: AuditLogListResponse.ServiceAccountUpdated;

  /**
   * The details for events with this `type`.
   */
  'user.added'?: AuditLogListResponse.UserAdded;

  /**
   * The details for events with this `type`.
   */
  'user.deleted'?: AuditLogListResponse.UserDeleted;

  /**
   * The details for events with this `type`.
   */
  'user.updated'?: AuditLogListResponse.UserUpdated;

  /**
   * The details for events with this `type`.
   */
  'workload_identity_provider_mapping.created'?: AuditLogListResponse.WorkloadIdentityProviderMappingCreated;

  /**
   * The details for events with this `type`.
   */
  'workload_identity_provider_mapping.deleted'?: AuditLogListResponse.WorkloadIdentityProviderMappingDeleted;

  /**
   * The details for events with this `type`.
   */
  'workload_identity_provider_mapping.updated'?: AuditLogListResponse.WorkloadIdentityProviderMappingUpdated;

  /**
   * The details for events with this `type`.
   */
  'workload_identity_provider.created'?: AuditLogListResponse.WorkloadIdentityProviderCreated;

  /**
   * The details for events with this `type`.
   */
  'workload_identity_provider.deleted'?: AuditLogListResponse.WorkloadIdentityProviderDeleted;

  /**
   * The details for events with this `type`.
   */
  'workload_identity_provider.updated'?: AuditLogListResponse.WorkloadIdentityProviderUpdated;
}

export namespace AuditLogListResponse {
  /**
   * The actor who performed the audit logged action.
   */
  export interface Actor {
    /**
     * The API Key used to perform the audit logged action.
     */
    api_key?: Actor.APIKey;

    /**
     * The session in which the audit logged action was performed.
     */
    session?: Actor.Session;

    /**
     * The type of actor. Is either `session` or `api_key`.
     */
    type?: 'session' | 'api_key';
  }

  export namespace Actor {
    /**
     * The API Key used to perform the audit logged action.
     */
    export interface APIKey {
      /**
       * The tracking id of the API key.
       */
      id?: string;

      /**
       * The service account that performed the audit logged action.
       */
      service_account?: APIKey.ServiceAccount;

      /**
       * The type of API key. Can be either `user` or `service_account`.
       */
      type?: 'user' | 'service_account';

      /**
       * The user who performed the audit logged action.
       */
      user?: APIKey.User;
    }

    export namespace APIKey {
      /**
       * The service account that performed the audit logged action.
       */
      export interface ServiceAccount {
        /**
         * The service account id.
         */
        id?: string;
      }

      /**
       * The user who performed the audit logged action.
       */
      export interface User {
        /**
         * The user id.
         */
        id?: string;

        /**
         * The user email.
         */
        email?: string;
      }
    }

    /**
     * The session in which the audit logged action was performed.
     */
    export interface Session {
      /**
       * The IP address from which the action was performed.
       */
      ip_address?: string;

      /**
       * The user who performed the audit logged action.
       */
      user?: Session.User;
    }

    export namespace Session {
      /**
       * The user who performed the audit logged action.
       */
      export interface User {
        /**
         * The user id.
         */
        id?: string;

        /**
         * The user email.
         */
        email?: string;
      }
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface APIKeyCreated {
    /**
     * The tracking ID of the API key.
     */
    id?: string;

    /**
     * The payload used to create the API key.
     */
    data?: APIKeyCreated.Data;
  }

  export namespace APIKeyCreated {
    /**
     * The payload used to create the API key.
     */
    export interface Data {
      /**
       * A list of scopes allowed for the API key, e.g. `["api.model.request"]`
       */
      scopes?: Array<string>;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface APIKeyDeleted {
    /**
     * The tracking ID of the API key.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface APIKeyUpdated {
    /**
     * The tracking ID of the API key.
     */
    id?: string;

    /**
     * The payload used to update the API key.
     */
    changes_requested?: APIKeyUpdated.ChangesRequested;
  }

  export namespace APIKeyUpdated {
    /**
     * The payload used to update the API key.
     */
    export interface ChangesRequested {
      /**
       * A list of scopes allowed for the API key, e.g. `["api.model.request"]`
       */
      scopes?: Array<string>;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface CertificateCreated {
    /**
     * The certificate ID.
     */
    id?: string;

    /**
     * The name of the certificate.
     */
    name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface CertificateDeleted {
    /**
     * The certificate ID.
     */
    id?: string;

    /**
     * The certificate content in PEM format.
     */
    certificate?: string;

    /**
     * The name of the certificate.
     */
    name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface CertificateUpdated {
    /**
     * The certificate ID.
     */
    id?: string;

    /**
     * The name of the certificate.
     */
    name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface CertificatesActivated {
    certificates?: Array<CertificatesActivated.Certificate>;
  }

  export namespace CertificatesActivated {
    export interface Certificate {
      /**
       * The certificate ID.
       */
      id?: string;

      /**
       * The name of the certificate.
       */
      name?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface CertificatesDeactivated {
    certificates?: Array<CertificatesDeactivated.Certificate>;
  }

  export namespace CertificatesDeactivated {
    export interface Certificate {
      /**
       * The certificate ID.
       */
      id?: string;

      /**
       * The name of the certificate.
       */
      name?: string;
    }
  }

  /**
   * The project and fine-tuned model checkpoint that the checkpoint permission was
   * created for.
   */
  export interface CheckpointPermissionCreated {
    /**
     * The ID of the checkpoint permission.
     */
    id?: string;

    /**
     * The payload used to create the checkpoint permission.
     */
    data?: CheckpointPermissionCreated.Data;
  }

  export namespace CheckpointPermissionCreated {
    /**
     * The payload used to create the checkpoint permission.
     */
    export interface Data {
      /**
       * The ID of the fine-tuned model checkpoint.
       */
      fine_tuned_model_checkpoint?: string;

      /**
       * The ID of the project that the checkpoint permission was created for.
       */
      project_id?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface CheckpointPermissionDeleted {
    /**
     * The ID of the checkpoint permission.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ExternalKeyRegistered {
    /**
     * The ID of the external key configuration.
     */
    id?: string;

    /**
     * The configuration for the external key.
     */
    data?: unknown;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ExternalKeyRemoved {
    /**
     * The ID of the external key configuration.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ExternalStorageRegistered {
    /**
     * The ID of the external storage configuration.
     */
    id?: string;

    /**
     * The configuration for the external storage.
     */
    data?: ExternalStorageRegistered.Data;
  }

  export namespace ExternalStorageRegistered {
    /**
     * The configuration for the external storage.
     */
    export interface Data {
      /**
       * The OpenAI geography derived from the storage region.
       */
      geography?: string;

      /**
       * The external storage provider configuration.
       */
      provider?:
        | ExternalStorageAPI.AwsExternalStorageProvider
        | ExternalStorageAPI.AzureExternalStorageProvider;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface ExternalStorageRemoved {
    /**
     * The ID of the external storage configuration.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface GroupCreated {
    /**
     * The ID of the group.
     */
    id?: string;

    /**
     * Information about the created group.
     */
    data?: GroupCreated.Data;
  }

  export namespace GroupCreated {
    /**
     * Information about the created group.
     */
    export interface Data {
      /**
       * The group name.
       */
      group_name?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface GroupDeleted {
    /**
     * The ID of the group.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface GroupUpdated {
    /**
     * The ID of the group.
     */
    id?: string;

    /**
     * The payload used to update the group.
     */
    changes_requested?: GroupUpdated.ChangesRequested;
  }

  export namespace GroupUpdated {
    /**
     * The payload used to update the group.
     */
    export interface ChangesRequested {
      /**
       * The updated group name.
       */
      group_name?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface InviteAccepted {
    /**
     * The ID of the invite.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface InviteDeleted {
    /**
     * The ID of the invite.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface InviteSent {
    /**
     * The ID of the invite.
     */
    id?: string;

    /**
     * The payload used to create the invite.
     */
    data?: InviteSent.Data;
  }

  export namespace InviteSent {
    /**
     * The payload used to create the invite.
     */
    export interface Data {
      /**
       * The email invited to the organization.
       */
      email?: string;

      /**
       * The role the email was invited to be. Is either `owner` or `member`.
       */
      role?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface IPAllowlistConfigActivated {
    /**
     * The configurations that were activated.
     */
    configs?: Array<IPAllowlistConfigActivated.Config>;
  }

  export namespace IPAllowlistConfigActivated {
    export interface Config {
      /**
       * The ID of the IP allowlist configuration.
       */
      id?: string;

      /**
       * The name of the IP allowlist configuration.
       */
      name?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface IPAllowlistConfigDeactivated {
    /**
     * The configurations that were deactivated.
     */
    configs?: Array<IPAllowlistConfigDeactivated.Config>;
  }

  export namespace IPAllowlistConfigDeactivated {
    export interface Config {
      /**
       * The ID of the IP allowlist configuration.
       */
      id?: string;

      /**
       * The name of the IP allowlist configuration.
       */
      name?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface IPAllowlistCreated {
    /**
     * The ID of the IP allowlist configuration.
     */
    id?: string;

    /**
     * The IP addresses or CIDR ranges included in the configuration.
     */
    allowed_ips?: Array<string>;

    /**
     * The name of the IP allowlist configuration.
     */
    name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface IPAllowlistDeleted {
    /**
     * The ID of the IP allowlist configuration.
     */
    id?: string;

    /**
     * The IP addresses or CIDR ranges that were in the configuration.
     */
    allowed_ips?: Array<string>;

    /**
     * The name of the IP allowlist configuration.
     */
    name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface IPAllowlistUpdated {
    /**
     * The ID of the IP allowlist configuration.
     */
    id?: string;

    /**
     * The updated set of IP addresses or CIDR ranges in the configuration.
     */
    allowed_ips?: Array<string>;
  }

  /**
   * The details for events with this `type`.
   */
  export interface LoginFailed {
    /**
     * The error code of the failure.
     */
    error_code?: string;

    /**
     * The error message of the failure.
     */
    error_message?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface LogoutFailed {
    /**
     * The error code of the failure.
     */
    error_code?: string;

    /**
     * The error message of the failure.
     */
    error_message?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface OrganizationUpdated {
    /**
     * The organization ID.
     */
    id?: string;

    /**
     * The payload used to update the organization settings.
     */
    changes_requested?: OrganizationUpdated.ChangesRequested;
  }

  export namespace OrganizationUpdated {
    /**
     * The payload used to update the organization settings.
     */
    export interface ChangesRequested {
      /**
       * How your organization logs data from supported API calls. One of `disabled`,
       * `enabled_per_call`, `enabled_for_all_projects`, or
       * `enabled_for_selected_projects`
       */
      api_call_logging?: string;

      /**
       * The list of project ids if api_call_logging is set to
       * `enabled_for_selected_projects`
       */
      api_call_logging_project_ids?: string;

      /**
       * The organization description.
       */
      description?: string;

      /**
       * The organization name.
       */
      name?: string;

      /**
       * Visibility of the threads page which shows messages created with the Assistants
       * API and Playground. One of `ANY_ROLE`, `OWNERS`, or `NONE`.
       */
      threads_ui_visibility?: string;

      /**
       * The organization title.
       */
      title?: string;

      /**
       * Visibility of the usage dashboard which shows activity and costs for your
       * organization. One of `ANY_ROLE` or `OWNERS`.
       */
      usage_dashboard_visibility?: string;
    }
  }

  /**
   * The project that the action was scoped to. Absent for actions not scoped to
   * projects. Note that any admin actions taken via Admin API keys are associated
   * with the default project.
   */
  export interface Project {
    /**
     * The project ID.
     */
    id?: string;

    /**
     * The project title.
     */
    name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ProjectArchived {
    /**
     * The project ID.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ProjectCreated {
    /**
     * The project ID.
     */
    id?: string;

    /**
     * The payload used to create the project.
     */
    data?: ProjectCreated.Data;
  }

  export namespace ProjectCreated {
    /**
     * The payload used to create the project.
     */
    export interface Data {
      /**
       * The project name.
       */
      name?: string;

      /**
       * The title of the project as seen on the dashboard.
       */
      title?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface ProjectDeleted {
    /**
     * The project ID.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ProjectUpdated {
    /**
     * The project ID.
     */
    id?: string;

    /**
     * The payload used to update the project.
     */
    changes_requested?: ProjectUpdated.ChangesRequested;
  }

  export namespace ProjectUpdated {
    /**
     * The payload used to update the project.
     */
    export interface ChangesRequested {
      /**
       * The title of the project as seen on the dashboard.
       */
      title?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface RateLimitDeleted {
    /**
     * The rate limit ID
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface RateLimitUpdated {
    /**
     * The rate limit ID
     */
    id?: string;

    /**
     * The payload used to update the rate limits.
     */
    changes_requested?: RateLimitUpdated.ChangesRequested;
  }

  export namespace RateLimitUpdated {
    /**
     * The payload used to update the rate limits.
     */
    export interface ChangesRequested {
      /**
       * The maximum batch input tokens per day. Only relevant for certain models.
       */
      batch_1_day_max_input_tokens?: number;

      /**
       * The maximum audio megabytes per minute. Only relevant for certain models.
       */
      max_audio_megabytes_per_1_minute?: number;

      /**
       * The maximum images per minute. Only relevant for certain models.
       */
      max_images_per_1_minute?: number;

      /**
       * The maximum requests per day. Only relevant for certain models.
       */
      max_requests_per_1_day?: number;

      /**
       * The maximum requests per minute.
       */
      max_requests_per_1_minute?: number;

      /**
       * The maximum tokens per minute.
       */
      max_tokens_per_1_minute?: number;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface RoleAssignmentCreated {
    /**
     * The identifier of the role assignment.
     */
    id?: string;

    /**
     * The principal (user or group) that received the role.
     */
    principal_id?: string;

    /**
     * The type of principal (user or group) that received the role.
     */
    principal_type?: string;

    /**
     * The resource the role assignment is scoped to.
     */
    resource_id?: string;

    /**
     * The type of resource the role assignment is scoped to.
     */
    resource_type?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface RoleAssignmentDeleted {
    /**
     * The identifier of the role assignment.
     */
    id?: string;

    /**
     * The principal (user or group) that had the role removed.
     */
    principal_id?: string;

    /**
     * The type of principal (user or group) that had the role removed.
     */
    principal_type?: string;

    /**
     * The resource the role assignment was scoped to.
     */
    resource_id?: string;

    /**
     * The type of resource the role assignment was scoped to.
     */
    resource_type?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface RoleBoundToResource {
    /**
     * The ID of the resource the role was bound to. ChatGPT workspace connector
     * resources use `<workspace_id>__<connector_id>`.
     */
    id?: string;

    /**
     * The connector ID for a ChatGPT workspace connector resource.
     */
    connector_id?: string;

    /**
     * The connector display name for a ChatGPT workspace connector resource, or the
     * connector ID when the display name could not be resolved.
     */
    connector_name?: string;

    /**
     * Whether the connector is enabled for the role.
     */
    enabled?: boolean;

    /**
     * The permissions granted to the role for the resource.
     */
    permissions?: Array<string>;

    /**
     * The ID of the resource the role was bound to.
     */
    resource_id?: string;

    /**
     * The type of resource the role was bound to.
     */
    resource_type?: string;

    /**
     * The ID of the role that was bound to the resource.
     */
    role_id?: string;

    /**
     * The connector role mutation path that produced the event.
     */
    source?:
      | 'role_toggle'
      | 'role_connector_update'
      | 'role_delete'
      | 'workspace_permissions'
      | 'connector_publish';

    /**
     * The workspace ID for a ChatGPT workspace connector resource.
     */
    workspace_id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface RoleCreated {
    /**
     * The role ID.
     */
    id?: string;

    /**
     * The permissions granted by the role.
     */
    permissions?: Array<string>;

    /**
     * The resource the role is scoped to.
     */
    resource_id?: string;

    /**
     * The type of resource the role belongs to.
     */
    resource_type?: string;

    /**
     * The name of the role.
     */
    role_name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface RoleDeleted {
    /**
     * The role ID.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface RoleUnboundFromResource {
    /**
     * The ID of the resource the role was unbound from. ChatGPT workspace connector
     * resources use `<workspace_id>__<connector_id>`.
     */
    id?: string;

    /**
     * The connector ID for a ChatGPT workspace connector resource.
     */
    connector_id?: string;

    /**
     * The connector display name for a ChatGPT workspace connector resource, or the
     * connector ID when the display name could not be resolved.
     */
    connector_name?: string;

    /**
     * Whether the connector is enabled for the role.
     */
    enabled?: boolean;

    /**
     * The permissions remaining for the role after the change.
     */
    permissions?: Array<string>;

    /**
     * The ID of the resource the role was unbound from.
     */
    resource_id?: string;

    /**
     * The type of resource the role was unbound from.
     */
    resource_type?: string;

    /**
     * The ID of the role that was unbound from the resource.
     */
    role_id?: string;

    /**
     * The connector role mutation path that produced the event.
     */
    source?:
      | 'role_toggle'
      | 'role_connector_update'
      | 'role_delete'
      | 'workspace_permissions'
      | 'connector_publish';

    /**
     * The workspace ID for a ChatGPT workspace connector resource.
     */
    workspace_id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface RoleUpdated {
    /**
     * The role ID.
     */
    id?: string;

    /**
     * The payload used to update the role.
     */
    changes_requested?: RoleUpdated.ChangesRequested;
  }

  export namespace RoleUpdated {
    /**
     * The payload used to update the role.
     */
    export interface ChangesRequested {
      /**
       * The updated role description, when provided.
       */
      description?: string;

      /**
       * Additional metadata stored on the role.
       */
      metadata?: unknown;

      /**
       * The permissions added to the role.
       */
      permissions_added?: Array<string>;

      /**
       * The permissions removed from the role.
       */
      permissions_removed?: Array<string>;

      /**
       * The resource the role is scoped to.
       */
      resource_id?: string;

      /**
       * The type of resource the role belongs to.
       */
      resource_type?: string;

      /**
       * The updated role name, when provided.
       */
      role_name?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface ScimDisabled {
    /**
     * The ID of the SCIM was disabled for.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ScimEnabled {
    /**
     * The ID of the SCIM was enabled for.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ServiceAccountCreated {
    /**
     * The service account ID.
     */
    id?: string;

    /**
     * The payload used to create the service account.
     */
    data?: ServiceAccountCreated.Data;
  }

  export namespace ServiceAccountCreated {
    /**
     * The payload used to create the service account.
     */
    export interface Data {
      /**
       * The role of the service account. Is either `owner` or `member`.
       */
      role?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface ServiceAccountDeleted {
    /**
     * The service account ID.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface ServiceAccountUpdated {
    /**
     * The service account ID.
     */
    id?: string;

    /**
     * The payload used to updated the service account.
     */
    changes_requested?: ServiceAccountUpdated.ChangesRequested;
  }

  export namespace ServiceAccountUpdated {
    /**
     * The payload used to updated the service account.
     */
    export interface ChangesRequested {
      /**
       * The role of the service account. Is either `owner` or `member`.
       */
      role?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface UserAdded {
    /**
     * The user ID.
     */
    id?: string;

    /**
     * The payload used to add the user to the project.
     */
    data?: UserAdded.Data;
  }

  export namespace UserAdded {
    /**
     * The payload used to add the user to the project.
     */
    export interface Data {
      /**
       * The role of the user. Is either `owner` or `member`.
       */
      role?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface UserDeleted {
    /**
     * The user ID.
     */
    id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface UserUpdated {
    /**
     * The project ID.
     */
    id?: string;

    /**
     * The payload used to update the user.
     */
    changes_requested?: UserUpdated.ChangesRequested;
  }

  export namespace UserUpdated {
    /**
     * The payload used to update the user.
     */
    export interface ChangesRequested {
      /**
       * The role of the user. Is either `owner` or `member`.
       */
      role?: string;
    }
  }

  /**
   * The details for events with this `type`.
   */
  export interface WorkloadIdentityProviderMappingCreated {
    /**
     * The workload identity provider mapping ID.
     */
    id?: string;

    /**
     * The payload used to create the workload identity provider mapping.
     */
    data?: unknown;

    /**
     * The workload identity provider ID.
     */
    identity_provider_id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface WorkloadIdentityProviderMappingDeleted {
    /**
     * The workload identity provider mapping ID.
     */
    id?: string;

    /**
     * The workload identity provider ID.
     */
    identity_provider_id?: string;

    /**
     * The project ID.
     */
    project_id?: string;

    /**
     * The mapped service account ID.
     */
    service_account_id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface WorkloadIdentityProviderMappingUpdated {
    /**
     * The workload identity provider mapping ID.
     */
    id?: string;

    /**
     * The payload used to update the workload identity provider mapping.
     */
    changes_requested?: unknown;

    /**
     * The workload identity provider ID.
     */
    identity_provider_id?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface WorkloadIdentityProviderCreated {
    /**
     * The workload identity provider ID.
     */
    id?: string;

    /**
     * The payload used to create the workload identity provider.
     */
    data?: unknown;
  }

  /**
   * The details for events with this `type`.
   */
  export interface WorkloadIdentityProviderDeleted {
    /**
     * The workload identity provider ID.
     */
    id?: string;

    /**
     * The workload identity provider name.
     */
    name?: string;
  }

  /**
   * The details for events with this `type`.
   */
  export interface WorkloadIdentityProviderUpdated {
    /**
     * The workload identity provider ID.
     */
    id?: string;

    /**
     * The payload used to update the workload identity provider.
     */
    changes_requested?: unknown;
  }
}

export interface AuditLogListParams extends ConversationCursorPageParams {
  /**
   * Return only events performed by users with these emails.
   */
  actor_emails?: Array<string>;

  /**
   * Return only events performed by these actors. Can be a user ID, a service
   * account ID, or an api key tracking ID.
   */
  actor_ids?: Array<string>;

  /**
   * A cursor for use in pagination. `before` is an object ID that defines your place
   * in the list. For instance, if you make a list request and receive 100 objects,
   * starting with obj_foo, your subsequent call can include before=obj_foo in order
   * to fetch the previous page of the list.
   */
  before?: string;

  /**
   * Return only events whose `effective_at` (Unix seconds) is in this range.
   */
  effective_at?: AuditLogListParams.EffectiveAt;

  /**
   * Return only events with a `type` in one of these values. For example,
   * `project.created`. For all options, see the documentation for the
   * [audit log object](https://developers.openai.com/api/reference/resources/admin/subresources/organization/subresources/audit_logs).
   */
  event_types?: Array<
    | 'api_key.created'
    | 'api_key.updated'
    | 'api_key.deleted'
    | 'certificate.created'
    | 'certificate.updated'
    | 'certificate.deleted'
    | 'certificates.activated'
    | 'certificates.deactivated'
    | 'checkpoint.permission.created'
    | 'checkpoint.permission.deleted'
    | 'external_key.registered'
    | 'external_key.removed'
    | 'external_storage.registered'
    | 'external_storage.removed'
    | 'group.created'
    | 'group.updated'
    | 'group.deleted'
    | 'invite.sent'
    | 'invite.accepted'
    | 'invite.deleted'
    | 'ip_allowlist.created'
    | 'ip_allowlist.updated'
    | 'ip_allowlist.deleted'
    | 'ip_allowlist.config.activated'
    | 'ip_allowlist.config.deactivated'
    | 'login.succeeded'
    | 'login.failed'
    | 'logout.succeeded'
    | 'logout.failed'
    | 'organization.updated'
    | 'project.created'
    | 'project.updated'
    | 'project.archived'
    | 'project.deleted'
    | 'rate_limit.updated'
    | 'rate_limit.deleted'
    | 'resource.deleted'
    | 'tunnel.created'
    | 'tunnel.updated'
    | 'tunnel.deleted'
    | 'workload_identity_provider.created'
    | 'workload_identity_provider.updated'
    | 'workload_identity_provider.deleted'
    | 'workload_identity_provider_mapping.created'
    | 'workload_identity_provider_mapping.updated'
    | 'workload_identity_provider_mapping.deleted'
    | 'role.created'
    | 'role.updated'
    | 'role.deleted'
    | 'role.assignment.created'
    | 'role.assignment.deleted'
    | 'role.bound_to_resource'
    | 'role.unbound_from_resource'
    | 'scim.enabled'
    | 'scim.disabled'
    | 'service_account.created'
    | 'service_account.updated'
    | 'service_account.deleted'
    | 'user.added'
    | 'user.updated'
    | 'user.deleted'
    | 'tenant.metadata.updated'
    | 'tenant.microsoft_entra_mapping.upserted'
    | 'tenant.microsoft_entra_mapping.deleted'
    | 'tenant.workload_identity.provider.created'
    | 'tenant.workload_identity.provider.updated'
    | 'tenant.workload_identity.provider.archived'
    | 'tenant.workload_identity.mapping.created'
    | 'tenant.workload_identity.mapping.updated'
    | 'tenant.workload_identity.mapping.archived'
    | 'tenant.workload_identity.binding.created'
    | 'tenant.workload_identity.principal.provisioned'
    | 'tenant.workload_identity.access_token.issued'
    | 'tenant.admin_api_key.created'
    | 'tenant.admin_api_key.updated'
    | 'tenant.admin_api_key.deleted'
    | 'tenant.project_api_key.created'
    | 'tenant.trusted_access.business_verification.started'
    | 'tenant.trusted_access.application.submitted'
    | 'tenant.chatgpt_access_token.revoked'
    | 'tenant.migration.completed'
    | 'tenant.sso.migrated'
    | 'tenant.domains.migrated'
    | 'tenant.sso_connection.created'
    | 'tenant.sso_connection.updated'
    | 'tenant.sso_connection.deleted'
    | 'tenant.sso_connection.setup.started'
    | 'tenant.policy.created'
    | 'tenant.policy.updated'
    | 'tenant.policy.deleted'
    | 'tenant.policy.attached'
    | 'tenant.policy.detached'
    | 'tenant.principal_authentication_policy.resolved'
    | 'tenant.scim.setup.started'
    | 'tenant.scim.deletion.requested'
    | 'tenant.scim.directory.created'
    | 'tenant.product_access_policy.updated'
    | 'tenant.resource_share_grant.created'
    | 'tenant.resource_share_grant.updated'
    | 'tenant.resource_share_grant.accepted'
    | 'tenant.resource_share_grant.declined'
    | 'tenant.resource_share_grant.revoked'
    | 'tenant.resource_share_grant.deleted'
    | 'tenant.service_account.updated'
    | 'tenant.service_account.deleted'
    | 'tenant.service_account.token.revoked'
    | 'tenant.billing.overage_limit.updated'
    | 'tenant.billing.alerts.updated'
    | 'tenant.billing.info.updated'
    | 'tenant.usage_limit.workspace.updated'
    | 'tenant.usage_limit.group.updated'
    | 'tenant.usage_limit.user.updated'
    | 'tenant.usage_limit.increase_request.updated'
    | 'tenant.usage_limit.increase_request.resolved'
    | 'tenant.group.created'
    | 'tenant.group.updated'
    | 'tenant.group.deleted'
    | 'tenant.group.member.added'
    | 'tenant.group.member.removed'
    | 'tenant.migration_rollout.status.updated'
    | 'tenant.migration_rollout.tier.updated'
    | 'tenant.role.metadata.updated'
    | 'tenant.custom_role.created'
    | 'tenant.custom_role.updated'
    | 'tenant.custom_role.deleted'
    | 'tenant.role_assignment.created'
    | 'tenant.role_assignment.deleted'
    | 'tenant.resource_role_assignment.created'
    | 'tenant.resource_role_assignment.deleted'
    | 'tenant.resource_access.updated'
    | 'tenant.resource_access.deleted'
    | 'tenant.ads_account.onboarding.redemption'
    | 'tenant.session_policy.created'
    | 'tenant.session_policy.updated'
    | 'tenant.session_policy.deleted'
    | 'tenant.session_revocation.started'
    | 'tenant.third_party_app_policy.updated'
    | 'tenant.user.added'
    | 'tenant.user.updated'
    | 'tenant.user.removed'
    | 'tenant.user.looked_up'
    | 'tenant.user.invited'
    | 'tenant.membership.revoked'
    | 'tenant.api_organization_invite.upserted'
    | 'tenant.api_organization_invite.deleted'
    | 'tenant.chatgpt_workspace_invite.upserted'
    | 'tenant.membership.accepted'
    | 'tenant.membership.declined'
    | 'tenant.workspace_invite_email_settings.updated'
  >;

  /**
   * Return only events for these projects.
   */
  project_ids?: Array<string>;

  /**
   * Return only events performed on these targets. For example, a project ID
   * updated. For ChatGPT connector role events, use the workspace connector resource
   * ID shown in `details.id`, such as `<workspace_id>__<connector_id>`.
   */
  resource_ids?: Array<string>;

  /**
   * Return only tenant-scoped events associated with this organization. Required for
   * tenant-scoped events such as `role.bound_to_resource` and
   * `role.unbound_from_resource`. When `true`, all supplied event types must be
   * tenant-scoped.
   */
  tenant_only?: boolean;
}

export namespace AuditLogListParams {
  /**
   * Return only events whose `effective_at` (Unix seconds) is in this range.
   */
  export interface EffectiveAt {
    /**
     * Return only events whose `effective_at` (Unix seconds) is greater than this
     * value.
     */
    gt?: number;

    /**
     * Return only events whose `effective_at` (Unix seconds) is greater than or equal
     * to this value.
     */
    gte?: number;

    /**
     * Return only events whose `effective_at` (Unix seconds) is less than this value.
     */
    lt?: number;

    /**
     * Return only events whose `effective_at` (Unix seconds) is less than or equal to
     * this value.
     */
    lte?: number;
  }
}

export declare namespace AuditLogs {
  export {
    type AuditLogListResponse as AuditLogListResponse,
    type AuditLogListResponsesPage as AuditLogListResponsesPage,
    type AuditLogListParams as AuditLogListParams,
  };
}
