As an admin, we are addressing logging and monitoring policies in our company. We would like to capture a log of API calls made to a specific Aha instance.
We are aware that you have an activity webhook that will notify our system of every change to a domain object (Feature, Release, etc) in Aha; however, it does not provide the view of the numerous API Calls as any user with access into an instance can generate an API Key.
API log should have information on the API key used, time of access, what data was accessed, how was it accessed (read, create, delete, update), etc.
Huge risk as we have no visibility of who is accessing Aha data via a back door. Aha APIs should never be accessible via 'Personal' settings without some was for SysAdmins to monitor who is this
Our security team is very concerned that we don't have a mechanism for reporting on who and what API keys have been created as an individual once they generate that API key could access Aha outside of our ecosystem. It's a matter of maintaining record in order to define potentially bad actors.
This is absolutely critical. Currently, as an administrator, I have no visibility on integrations that have been created by end users via the Aha! Reset API and also have no way of restricting those user's ability to create integrations or interacting with the Aha! API.