Read more about Asana’s support for Audit Log, Security Information and Event Management (SIEM), Data Loss Prevention (DLP), eDiscovery, Archiving, and Cloud Access Security Broker (CASB) use cases.
Asana’s Compliance Management APIs and Apps support your organization’s security and compliance posture. You can read more about the full suite of Compliance Management addon features here. Our Compliance Management APIs currently offer:
Currently these are only available to Asana Enterprise+ tier, Legacy Enterprise tier, or organization-wide Enterprise subscriptions with the purchase of the Compliance Management add-on.
If you would like to learn more about our Compliance Management features, please contact your sales representative.
Asana’s Audit Log API provides super admins access to an immutable log of key events across their organization. Using the Audit Log API, super admins can capture and act upon important security and compliance related changes.
Super admins can use Asana’s Audit Log API to:
Asana’s audit log API includes dozens of events, including:
workspace_export_started, workspace_password_requirements_changed, and user_workspace_admin_role_changeduser_login_succeeded, user_login_failed, user_invited,and team_member_addedtask_deleted, task_undeleted, and portfolio_deletedproject_csv_export_initiated and workspace_teams_export_startedattachment_uploaded and attachment_downloadedFor a full list and details around the API endpoint, visit the API documentation
Asana stores audit logs for 90 days from the date of capture. Those who would like a longer retention period may choose to use their SIEM or another storage solution for continuous log ingestion.
Audit logs are accessible to super admins via service accounts. To see a detailed description of the audit log API endpoint, check out our developer documentation here.
To learn more about using Asana’s audit log API via Asana’s Splunk integration, visit Splunkbase to begin the installation process.
To learn more about using Asana’s audit log API via Asana’s Panther integration, visit their Asana Apps page.
You can export a CSV of audit log events directly from the admin console. This is useful when you need a quick snapshot for incident review or want to share event data with stakeholders without setting up the audit log API.
To export a CSV of audit log events:
Once you are ready to export your audit log, click Request export. Your export will be emailed to you.
Customers may wish to regularly scan their Asana instances for data that affects or violates their organization-wide policies.
For example, an organization may wish to conduct a monthly audit to find any instances of passwords being inadvertently entered into Asana tasks.
For customers and developers, to see a full list of details around the Resource Export API endpoint, visit the API documentation.
Note
For detail about Netskope’s integration with Asana, visit the Asana Apps page.
Customers may wish to pull data from Asana into a third-party eDiscovery tool to proactively plan for or reactively respond to litigation.
For customers and developers, to see a full list of details around the Resource Export API endpoint, visit the API documentation.
Note
Visit Exterro’s and Hanzo's Asana Apps page to learn more about their third party integrations with Asana. Stay tuned for additional partnerships coming soon.
Customers in highly-regulated industries may wish to regularly pull/store objects or events related to changes on objects in Asana.
For customers and developers, to see a full list of details around the Resource Export API endpoint, visit the API documentation.
Note
Learn more about Theta Lake's integration with Asana by visiting their Asana Apps page
Customers may wish to control use of Asana via their Cloud Access Security Broker (CASB) provider. Asana currently offers a connector with Netskope and support for setting approved workspaces. Please visit this article to learn more about managing approved workspaces.
Note
For detail about Netskope’s integration with Asana, visit the Asana Apps page.