- User / Agent
- Taylor Brooks
via Copilot
- Account
- Supplier Admins
Observability & Audit · Action and audit logs. Audit how your teams use AI agents across business systems.
Review action outcomes and the policies evaluated.
| User / Agent | System / Action | Outcome / Checks |
|---|---|---|
| Taylor Brooks | SAP S/4HANA | 200 2 Clean |
| Noah Patel | Jamf Pro | 200 2 Clean |
| Alex Morgan | Workday | 200 3 Clean |
| Lena Ortiz | Salesforce | 200 2 Clean |
| Priya Shah | Xero | 403 3 Not run |
| Sam Rivera | ServiceNow | 201 2 Clean |
| Alex Morgan | Workday | 200 3 Clean |
- User / Agent
- Noah Patel
via Claude Code
- Account
- IT Support
- User / Agent
- Alex Morgan
via Claude
- Account
- People Operations
- User / Agent
- Lena Ortiz
via Copilot
- Account
- Revenue reporting
- User / Agent
- Priya Shah
via Claude Code
- Account
- Finance
- User / Agent
- Sam Rivera
via Claude Code
- Account
- IT requests
- User / Agent
- Alex Morgan
via Claude Code
- Account
- People Operations
Action, platform and sign-in logs. Review tool calls, setup changes and sign-ins.
See the outcome of every tool call, setup change and sign-in.
| User / Agent | System / Action | Outcome |
|---|---|---|
| Jordan Blake | Salesforce | 200 198 ms |
| Sam Rivera | ServiceNow | 201 534 ms |
| Taylor Brooks | SAP S/4HANA | 404 126 ms |
| Alex Morgan | Workday | 200 286 ms |
| Noah Patel | Jamf Pro | 200 231 ms |
| Daniel Okafor | NetSuite | 200 412 ms |
| Priya Shah | Xero | 403 38 ms |
- Account
- Finance
- Decided by
- Restrict payment creation
- Policies evaluated
- 3
- Duration
- 38 ms
| Changed by | Change / Target | Result |
|---|---|---|
| API key No user recorded | Workday · People Operations | Success 201 Created |
| Noah Patel User session | Jamf Pro · IT Support | Success 200 OK |
| SCIM Directory sync | Finance approvers | Success 200 OK |
| Hannah Weiss User session | Xero · Finance approvers | Success 200 OK |
| Lena Ortiz User session | Restrict payment creation | Success 200 OK |
| API key No user recorded | Organization | Success 200 OK |
| Hannah Weiss User session | Finance reporting | Success 201 Created |
- Recorded user
- hannah@northwind.example
- Authentication
- User session
- Project
- Production
- HTTP result
- 201 Created
| Member | Event / Method | Result |
|---|---|---|
| Noah Patel noah@northwind.example | Dashboard | Success SAML |
| Hannah Weiss hannah@northwind.example | Dashboard | Success SAML |
| Ravi Menon ravi@northwind.example | All sessions | Revoked SCIM |
| Lena Ortiz lena@northwind.example | Dashboard | Success SAML |
| Maya Chen maya@northwind.example | Dashboard · Password | Failed SSO required |
| Jordan Blake jordan@northwind.example | ChatGPT | Success OAuth |
| Priya Shah priya@northwind.example | Claude Code | Success OAuth |
- Member
- priya@northwind.example
- Client
Claude Code
- Method
- OAuth consent
- Organization
- Northwind
Policy decision audit trail. Test a policy in Monitor only, then enforce it.
Monitor only records what a policy would have denied without blocking anyone. The logs show each decision before and after you switch.
Restrict payment creationCreate Payment in Xero · decisions per hour
Request and response logging. Keep request and response bodies.
Store the bodies of failed actions, or all of them, for up to 30 days, or as long as you need when you self-host.
SAP S/4HANA · Procurement
{
"error": {
"message":
"Supplier not found."
}
} Logs API and SIEM export. Send action and platform logs to your own tools.
Pull records through the Logs API to investigate agent activity or report on your rollout.
- POST
/Action and request logslogs - POST
/Setup changes made in StackOnelogs/ platform - POST
/Counts by connector, outcome or policy resultlogs/ stats/ aggregate - GET
/One tool calllogs/ actions/ {actionRunId} - GET
/The policy decision on that calllogs/ actions/ {actionRunId}/ policy
{ "data": [{"log_type": "action","event_time": "2026-09-21T12:45:19Z","action_id": "xero_create_payment","status_code": 403,"success": false,"duration_ms": 38}] } - Request
POST /logs- Basic auth
v1.eu1.xxxxx- Window
start_time= last pull
-
Datadog
-
Splunk
-
Elastic
-
Grafana
-
Snowflake
Connect your SIEM
Run a small collector or proxy that pulls records from the Logs API and forwards them to any SIEM or data platform.
Read the Logs API referenceFAQ. Questions about observability & audit
See what your teams' agents are doing.
Walk through action logs, policy decisions and export options for your rollout.