Chronicle is the enterprise command audit and compliance platform. Full trail visibility, policy-driven retention, surgical redaction, and instant replay — all in one mission-critical system.
Every feature maps to a real compliance requirement. Nothing extraneous. Everything auditable.
Complete, immutable record of every action taken across your organization. chronicle
renders the full chronological ledger with entry numbers, timestamps, and attribution.
Surface exactly the last N operations. Perfect for incident review windows and compliance spot-checks. Governance teams love the precision.
chronicle NFull history wipe for GDPR right-to-erasure requests. One command invocation clears the entire audit log when regulatory requirements demand it.
chronicle -cDelete specific entries by offset. When an operator accidentally logs sensitive credentials, redact the exact entry without disrupting the surrounding audit trail.
chronicle -d OFFSETAppend session activity to your designated audit file in real-time. No batch jobs. No overnight ETLs. Every command hits durable storage immediately.
chronicle -aReconstitute historical context from file-backed audit logs. New team members inherit institutional memory. Onboarding collapses from weeks to minutes.
chronicle -rWrite the entire current session state to a portable artifact. Ship it to compliance, attach it to incident reports, archive it for posterity.
chronicle -wRe-execute any previous action by reference number, recency, or pattern match. !!
replays the last action. !N replays by ID. !string matches by prefix.
Zero friction re-execution at scale.
Every command is recorded to a numbered, timestamped ledger. Chronicle captures each action the moment it executes — no agent required, no instrumentation overhead.
HISTCONTROL policies determine what gets recorded. ignoredups deduplicates.
ignorespace creates off-the-record zones. erasedups enforces
uniqueness retroactively.
Session data syncs to HISTFILE via chronicle -a, -w, and
-r. Configurable HISTSIZE and HISTFILESIZE ensure your retention windows match
regulatory requirements.
Any historical action can be re-executed with !!, !N, or
!string. The fc integration lets auditors edit and re-run entries for
remediation workflows.
Scroll through a live audit log. Click any entry to inspect, replay, or redact.
Define exactly what gets captured, how long it persists, and where it lives. Real-time policy preview below.
Real-time visibility into command activity across your organization.
Real commands. Real output. The same enterprise-grade audit experience your team deserves.
Start with the free tier. Scale to enterprise compliance as your governance requirements grow.
For individuals and small projects
chronicle — view full trailchronicle N — last N entries-d)-a/-w/-r)For teams that take compliance seriously
chronicle -d — Surgical Redactionchronicle -a/-w/-r — Persistence Suite!! / !N — Instant Replayfc integrationFor governance-first organizations
!string — pattern-based replayfc — Inline Remediationchronicle -n — Delta Syncerasedups policyFor regulated industries and public sector
!! to re-execute the last remediation step. No copy-paste. No
typos. Zero friction."-w flag lets us export snapshots directly to our GRC
platform. Compliance reviews that used to take days now take minutes."Chronicle's HISTCONTROL policy engine includes ignorespace mode — any command
prefixed with a space is automatically excluded from the audit trail. For pattern-based
exclusion, HISTIGNORE lets you define colon-separated patterns that are silently filtered. This
gives your operators the flexibility to work without compromising the audit surface.
Configure Chronicle with chronicle -a in your session hooks to continuously append
to HISTFILE. Combined with chronicle -n to read new entries from shared logs, your
audit data is durable even across unexpected terminations. We never lose a single entry.
Absolutely. HISTFILE can point to a shared location. Use chronicle -r to hydrate a
session from the shared log and chronicle -a to contribute back. The
-n flag reads only new entries appended since the last sync, preventing duplicates
and ensuring conflict-free multi-user audit trails.
Chronicle integrates with the fc subsystem, which opens any historical command in
your configured editor for modification before re-execution. This is what we call Inline
Remediation — fix-and-replay without leaving the audit context. Available on Team plans and
above.
HISTSIZE and HISTFILESIZE are declarative retention controls. Set them once, and Chronicle
enforces the limit automatically by evicting the oldest entries. Export the current
configuration with chronicle -w alongside your audit snapshots. Auditors get both
the data and the policy proof in one artifact.
Every regulated industry demands a complete audit trail. Financial services log every trade. Healthcare logs every access. Aviation logs every maintenance action. But the most powerful interface in technology — the command line — has operated in a governance vacuum. Operators execute commands that provision infrastructure, modify data, and configure security controls, and unless someone is watching, that activity vanishes.
Chronicle exists to close that gap. We believe that every command executed in a production environment is a compliance event. Every keystroke is an audit entry. Every session is a record that should be captured, governed, and retained according to policy — not left to chance. This is not about surveillance. It is about accountability, reproducibility, and the fundamental right of an organization to understand what happened and when.
We built Chronicle because the most consequential actions in technology still happen in the dark. Not anymore.