Audit log (AI agents)
An audit log is the durable record of what an AI agent did: the action attempted, the identity behind it, the time, and what happened next. It serves investigation, compliance evidence and forensics. It is a detective control by construction, describing actions that have already executed rather than deciding whether they should.
An agent audit log differs from an application one in volume and in who is expected to read it. A single coding agent can attempt thousands of actions in one working day, so a log that records everything and decides nothing moves the work to whoever reads it, and at that volume nobody does. What makes an entry useful is that it carries the decision as well as the event: what was attempted, which control applied, what the verdict was, and whether a person or an automatic mode answered when the action was held.
The failure mode worth designing against is silence. A recording path that breaks stops producing entries, and nothing about an empty log distinguishes a safe week from a control that quietly stopped enforcing. Logging permitted actions alongside refused ones is what turns that silence into something detectable, which is also what makes the record usable as evidence rather than telemetry.
Related
- The agent security stack
- Watch a decision get recorded
- Observability vs action governance
- All glossary terms
Shrike governs AI agent actions in real time: every command, query, and tool call evaluated against policy before it executes. Watch an agent get refused in the playground, where every tool call is scanned for real, or read what is action governance.