See what changed
Cloud History
Read cloud events and compare snapshots from your scans.
About 5 minutes
Cloud History shows changes across your connected clouds. Use the event timeline to see what happened, or compare two scan snapshots to see how resources changed.
Read the timeline
Open Cloud History → Timeline. Changes shows write events; Event history also includes read events where the provider supplies them. Live reads cloud audit logs now. Stored reads previously saved events. Set the time window, such as Last 7 days, and sort by Newest first or risk.
Filter by cloud and risk. The summary counts Critical, High risk, Outside IaC, and Total changes for the selected window. A demo can show All clouds 401, AWS 140, GCP 255, and DigitalOcean 6; your counts depend on your accounts and filters. Each event shows its name, cloud, risk, whether it was outside IaC, actor, tool used, account, time, and reasons such as identity changes or work outside Terraform.
Click an event for its details: time, actor, identity principal, source IP, tool, region, service, account, event ID, resource, user agent, and Raw event. Fields appear when the provider supplied them.
For a Beam grant, Undo the access can revoke the grant. Undo the change shows an inverse action when one can be described, such as deleting a bucket created by a CreateBucket event. A “reversible” badge describes that guidance. Zaysa does not execute the inverse cloud change for you; review and apply it yourself.
What each cloud needs
- AWS reads CloudTrail event history with LookupEvents through the connected identity. ReadOnlyAccess includes that permission. It reads the account's selected region and us-east-1 for global services. Changes includes writes only. An access problem appears as “CloudTrail access denied — grant cloudtrail:LookupEvents”.
- Google Cloud reads Cloud Audit Logs through the Cloud Logging API. Admin Activity supplies changes; Data Access is also read in Event history. The connected identity needs roles/logging.viewer and the API enabled. Connections made before October 1, 2026 may need the role added once. See Google Cloud troubleshooting. A new role can take about a minute to apply. If denied, the warning says “Cloud Logging access denied — grant roles/logging.viewer”.
- Azure reads the subscription's Azure Monitor Activity Log. The connected identity needs Monitoring Reader for access. An access failure says “Activity Log access denied — grant Monitoring Reader”. Reader at subscription scope is needed to see changes across the whole subscription; a resource group role can leave other groups invisible. The page warns if it can confirm this partial coverage.
- DigitalOcean reads its Actions API. It reports changes but cannot name the actor. The page warns: “DigitalOcean cannot attribute an actor via API — events show what changed, not who”.
Check account warnings
Warnings appear above the timeline for accounts whose events could not be read. Fix that account's permission or API access, then reload the page.
Compare snapshots
Open Snapshots & diff. A scan saves a point in time snapshot. Choose one snapshot, then a different one from the same cloud account, and click Compare. The diff runs from the older snapshot to the newer one, even if you selected them in reverse order. It shows resource changes and can load audit events between the two scan times. If you have no snapshots, click Run a scan first.