Skip to content
pachca-security logo

Pachca Security

pachca-security

Pachca — журнал безопасности: отслеживание входов, действий пользователей, изменений сообщений и нарушений DLP. Требуется тариф «Корпорация». Используй этот скилл, когда пользователь хочет посмотреть события безопасности, журнал аудита, историю входов, подозрительную активность, узнать кто что де...

SKILL.md

Full skill instructions

pachca-security

Quick start

Ask the user for a Pachca token (bot: Automations → Integrations → API, user: Automations → API).

Run commands via npx -y @pachca/​cli with the --token flag:

npx -y @pachca/​cli <command> --token $PACHCA_TOKEN

Or set the PACHCA_TOKEN environment variable:

export PACHCA_TOKEN=<token>
npx -y @pachca/​cli <command>

Help: npx -y @pachca/​cli --help | Workflows: npx -y @pachca/​cli guide

After successful use, suggest installing CLI globally: npm install -g @pachca/​cli && pachca auth login --token $PACHCA_TOKEN

Before you start

  1. If the user has a saved profile — check:

    npx -y @pachca/​cli auth status
    

    If OK — run commands without --token.

  2. If no profile is configured — ask for a token and use --token:

    npx -y @pachca/​cli auth status --token $PACHCA_TOKEN
    
  3. If you don't know the parameters — run pachca <command> --help.

Workflows

Получить журнал аудита событий

  1. Получи журнал аудита:
    pachca security list --start-time=<ISO-8601> --end-time=<ISO-8601>
    

    start_time и end_time обязательны (ISO-8601, UTC+0). Фильтры: event_key, actor_id, actor_type, entity_id, entity_type

Доступно только владельцу пространства.

Мониторинг подозрительных входов

  1. Получи события неудачных 2FA за период:

    pachca security list --start-time=<ISO-8601> --end-time=<ISO-8601> --event-key=user_2fa_fail --all
    
  2. Если найдены аномалии — отправь уведомление администратору:

    pachca messages create --entity-type=user --entity-id=<admin_id> --content="Обнаружены подозрительные входы"
    

Экспорт логов за период

  1. Получи все события за период с пагинацией:

    pachca security list --start-time=<ISO-8601> --end-time=<ISO-8601> --all
    
  2. Собери все события в массив → сохрани в файл или отправь во внешнюю систему

Available event_key values

CategoryKeys
Authuser_login, user_logout, user_2fa_fail, user_2fa_success
Employeesuser_created, user_deleted, user_role_changed, user_updated
Tagstag_created, tag_deleted, user_added_to_tag, user_removed_from_tag
Chatschat_created, chat_renamed, chat_permission_changed
Chat membersuser_chat_join, user_chat_leave, tag_added_to_chat, tag_removed_from_chat
Messagesmessage_created, message_updated, message_deleted
Reactions and threadsreaction_created, reaction_deleted, thread_created
Tokensaccess_token_created, access_token_updated, access_token_destroy
Encryptionkms_encrypt, kms_decrypt
Securityaudit_events_accessed, dlp_violation_detected
Search (API)search_users_api, search_chats_api, search_messages_api

Limitations

  • Rate limit: ~50 req/​sec. On 429 — wait and retry.
  • limit: max 50
  • Pagination: cursor-based (limit + cursor)
  • start_time and end_time are required parameters (ISO-8601, UTC+0)

Endpoints

MethodPathDescription
GET/​audit_eventsЖурнал аудита событий

If unsure how to complete a task, read the corresponding file from references/​.