Skip to main content Announcing Tool Gateway MCP: the universal MCPRead the announcement

Observability & Audit · Action and audit logs. Audit how your teams use AI agents across business systems.

Review action outcomes and the policies evaluated.

Northwind Production Action logs
Action logs
21 Sep 2026UTC
Recent actions Policies Defender
User / AgentSystem / ActionOutcome / Checks
Taylor Brooksvia Copilot
SAP S/4HANA
200 2 Clean
Noah Patelvia Claude Code
Jamf Pro
200 2 Clean
Alex Morganvia Claude
Workday
200 3 Clean
Lena Ortizvia Copilot
Salesforce
200 2 Clean
Priya Shahvia Claude Code
Xero
403 3 Not run
Sam Riveravia Claude Code
ServiceNow
201 2 Clean
Alex Morganvia Claude Code
Workday
200 3 Clean
Action details
Workday
Get Worker
200 OK Clean
User / Agent
Alex Morgan via Claude Code
Policies evaluated3
Protect personal dataMasked
EnforceMatchedResponse filtering
Field groupPersonal datapii

Personal data masked before reaching the agent.

Keep salaries unchangedNo match
Review worker lookupsMonitor onlyWould deny
2 other policiesNo match · Would deny
Worker lookup completed

Action, platform and sign-in logs. Review tool calls, setup changes and sign-ins.

See the outcome of every tool call, setup change and sign-in.

Northwind Action logs
Action logs
21 Sep 2026UTC
Recent actionsSelect a row for details
Action logs on 21 Sep 2026
User / AgentSystem / ActionOutcome
Jordan Blake via ChatGPT
Salesforce
200 198 ms
Sam Rivera via ChatGPT
ServiceNow
201 534 ms
Taylor Brooks via Copilot
SAP S/4HANA
404 126 ms
Alex Morgan via Claude
Workday
200 286 ms
Noah Patel via Claude Code
Jamf Pro
200 231 ms
Daniel Okafor via Claude
NetSuite
200 412 ms
Priya Shah via Claude Code
Xero
403 38 ms
Event details
Xero
Create Payment
403 Denied
Priya Shah via Claude Code
Account
Finance
Decided by
Restrict payment creation
Policies evaluated
3
Duration
38 ms
Payment refused by policy
Northwind Platform logs
Platform logs
21 Sep 2026UTC
Recent changesSelect a row for details
Platform logs on 21 Sep 2026
Changed byChange / TargetResult
API key No user recorded
Workday · People Operations
Success 201 Created
Noah Patel User session
Jamf Pro · IT Support
Success 200 OK
SCIM Directory sync
Finance approvers
Success 200 OK
Hannah Weiss User session
Xero · Finance approvers
Success 200 OK
Lena Ortiz User session
Restrict payment creation
Success 200 OK
API key No user recorded
Organization
Success 200 OK
Hannah Weiss User session
Finance reporting
Success 201 Created
Event details
Finance reporting
API key created
201 Created
Recorded user
hannah@northwind.example
Authentication
User session
Project
Production
HTTP result
201 Created
Key created in Production
Northwind Sign-in logs
Sign-in logs
21 Sep 2026UTC
Recent sign-insSelect a row for details
Sign-in logs on 21 Sep 2026
MemberEvent / MethodResult
Noah Patel noah@northwind.example
Dashboard
Success SAML
Hannah Weiss hannah@northwind.example
Dashboard
Success SAML
Ravi Menon ravi@northwind.example
All sessions
Revoked SCIM
Lena Ortiz lena@northwind.example
Dashboard
Success SAML
Maya Chen maya@northwind.example
Dashboard · Password
Failed SSO required
Jordan Blake jordan@northwind.example
ChatGPT
Success OAuth
Priya Shah priya@northwind.example
Claude Code
Success OAuth

Policy decision audit trail. Test a policy in Monitor only, then enforce it.

Monitor only records what a policy would have denied without blocking anyone. The logs show each decision before and after you switch.

Restrict payment creationCreate Payment in Xero · decisions per hour

The policy matched just as often after the switch. In Monitor only it logged each payment it would have stopped and blocked none; in Enforce it denied them.
Explore Permission Policies

Request and response logging. Keep request and response bodies.

Store the bodies of failed actions, or all of them, for up to 30 days, or as long as you need when you self-host.

Northwind Settings Advanced Logs
Try the settings
Data storage
Retention
New action with these settings
Get Supplier

SAP S/4HANA · Procurement

Action recorded
404 Not Found
Response excerptStored · 7 days
{
  "error": {
    "message":
      "Supplier not found."
  }
}

Logs API and SIEM export. Send action and platform logs to your own tools.

Pull records through the Logs API to investigate agent activity or report on your rollout.

StackOne
Logs API
api.stackone.com
  • POST /logs Action and request logs
  • POST /logs/platform Setup changes made in StackOne
  • POST /logs/stats/aggregate Counts by connector, outcome or policy result
  • GET /logs/actions/{actionRunId} One tool call
  • GET /logs/actions/{actionRunId}/policy The policy decision on that call
{ "data": [{"log_type": "action","event_time": "2026-09-21T12:45:19Z","action_id": "xero_create_payment","status_code": 403,"success": false,"duration_ms": 38}] }
Your network
Collector or proxy
Pulls every 5 minutes
Request
POST /logs
Basic auth
v1.eu1.xxxxx
Window
start_time = last pull
Your tools
Any SIEM or data platform
  • Datadog
  • Splunk
  • Elastic
  • Grafana
  • Snowflake
Grafana StackOne agent activity 24h
Tool calls1,284
Failed36
Denied24

Connect your SIEM

Run a small collector or proxy that pulls records from the Logs API and forwards them to any SIEM or data platform.

Read the Logs API reference

FAQ. Questions about observability & audit

See what your teams' agents are doing.

Walk through action logs, policy decisions and export options for your rollout.