Usage & Reports
Every role sees this card on the web under Settings → Team.
Budget Requests. A member or auditor presses Request more budget, types an amount and a reason, and sees their last five requests. An owner or admin sees pending ones with Grant for this month or Decline.
Budget Alerts. A seat with a budget emails the owner and the member at 80% and 100%.
Inventory & Results (owner, admin, auditor). Show the inventory lists who ran which model on whose credit, members idle for 30 days, and each project's owner, spend and live links. Show results has the model scoreboard, what moved since last month, objectives met or missed, rates, authorship by repository and seat, code health and contributions per member. Show devices lists each member's desktop, its version and whether it has the current policy; Governance can hide it. Each has a CSV for the month.
Audit & Logs
Owner or admin, on the web. The Mac shows a short version: Open this discussion's log, the rollout line, and the downloads below.
| Output | What it carries | How to set it |
|---|---|---|
| Audit Webhook | Every audit event as it happens | URL, Save; the signing secret is shown once. Send a test event |
| Alert Webhook | Budget stops, failed schedules, spend spikes | URL, Save, Send a test |
| OTLP Logs Endpoint | Events as OpenTelemetry logs | URL, Enter, optional Authorization header |
| S3 Audit Bucket | Events written to your bucket | Set: endpoint, bucket, region, access key, secret |
| Transcript Feed Bucket | Transcripts to your bucket. Members are told it is on | Same as the S3 bucket |
Delivery Status says which are set. Each webhook posts JSON with an X-LetThemChat-Signature header: sha256= followed by the hex HMAC-SHA256 of the exact body, keyed with the secret. Recompute it on receipt and drop anything that does not match. Which events exist, and their fields, is in the audit events pages.
The auditor pack (Download the auditor pack (30 days)) is the last thirty days of events in one file for someone outside the team. Mint an API key gives a bearer key for the compliance endpoint, shown once; Revoke ends it. Take everything (Download the team export) is the team's discussions, projects, members, policy, run records and audit events in one JSON file with a hash per section. Keys and secrets are not in it.

Advanced
Pause everything (owner or admin) stops every member's runs and takes their run tokens away, after a confirmation. Resume the team undoes it. Use it when a key leaks or spend runs away. The owner's Delete Team releases every seat and returns shared discussions to their authors. Everyone else sees Leave Team.
Further reading.
- NIST SP 800-92 Guide to Computer Security Log Management — Kent and Souppaya, 2006.
- RFC 2104 HMAC — Krawczyk, Bellare, Canetti, IETF, 1997.