Skip to main content

Audit Log

What the Audit Log captures​

Every action AI Partner takes that matters is logged to the audit trail. The Audit Log panel lets you query, filter, and review this trail with full context.

Go to sidebar → Settings → Audit Log (or navigate directly if it's in your sidebar).


Event categories​

CategoryWhat's logged
tool_callEvery MCP tool call: tool name, arguments, result, iteration, goal ID
goalGoal lifecycle: started, completed, failed, cancelled, paused, resumed
authorityEvery authority policy evaluation: action, counterparty, verdict (auto/ask/block)
approvalHITL approval events: question asked, user response (approved/edited/skipped), timeout
financialWrite operations on Stripe, HubSpot, S3, Sentry, Outlook — tamper-evident
securityLogin attempts, API key creation/revocation, permission changes
systemServer start/stop, migration runs, configuration changes
memoryMemory consolidation runs, biographic fact updates
meetingMeeting join, leave, transcript save, action item extraction

Using the Audit Log panel​

Filtering​

The panel has a filter bar at the top:

Category: [All ▼] Severity: [All ▼] User: [All ▼] Date: [Last 7 days ▼]
Search: _________________________ [Search]

Filter by category: tool_call, goal, authority, approval, financial, security, system
Filter by severity: info, warning, error
Filter by date range: last 24h, 7 days, 30 days, or custom
Full text search: searches event descriptions and metadata

Reading an entry​

2026-05-13 14:03:22 tool_call INFO
Action: web_search
Args: { "query": "Sequoia India fund 2026" }
Result: { "results": [...] }
Goal ID: goal_xyz789
Iteration: 3
Duration: 847ms

For authority decisions:

2026-05-13 14:05:11 authority INFO
Action: reply_email
Counterparty: sarah@acme.com (class: client)
Verdict: draft_and_ask
Outcome: approved (user tapped "Approve" at 14:05:34)
Telegram msg ID: 8745623

For financial operations:

2026-05-13 15:22:07 financial WARNING
Service: stripe
Action: stripe_issue_refund
Args: { "charge_id": "ch_xxx", "amount": 4999 }
Verdict: draft_and_ask → approved
Result: { "id": "re_xxx", "status": "succeeded" }
Hash: sha256:abc123... ← tamper-evident hash

Statistics view​

Switch to the Stats tab to see aggregate counts:

Last 7 days:
tool_call: 842 (↑18% vs. prior period)
goal: 47 (↑12%)
authority: 23 (8 auto, 12 ask, 3 block)
financial: 2 (all approved)
security: 1 (1 login)

By severity:
info: 903
warning: 9
error: 1

Financial audit log​

Financial write operations (Stripe, HubSpot, S3, Sentry, Outlook) have additional protections:

  • Each entry includes a SHA-256 hash of the operation parameters + timestamp + previous hash (chained)
  • This makes the log tamper-evident — if a record is modified or deleted, the chain breaks
  • The chain is verified on each page load; any broken chain shows a warning

This provides an auditable record suitable for financial compliance purposes.


Log retention​

Entries are kept for 90 days by default, after which the oldest are removed automatically. Retention is configurable on your instance, and an administrator can clear older entries deliberately.


Who can see what​

Your audit trail is yours. On a multi-user instance it's scoped strictly to your own login — one user can never read another's trail, and asking for someone else's doesn't work.

On a shared instance, administrators can see an organisation-wide view of activity, filterable per user. What they see is metadata — what happened, when, and with what verdict. They do not see the content: not your chats, not your messages, not your screenshots.

For compliance work: the financial trail is exportable in a structured form suitable for automated verification, which is what an auditor asking "prove nothing was paid without approval" actually needs.