Agent Security
What should an audit log capture for agent tool calls?

An audit log for agent tool calls should capture the agent identity, workflow or session ID, user or initiating context when relevant, tool name, operation, timestamp, policy decision, input/output metadata, success or failure result, and any downstream handoff. The goal is to make the execution explainable without exposing unnecessary sensitive content. For regulated or security-sensitive teams, the log should help answer what happened, why it was allowed, and what systems were touched. Diagrid emphasizes audit-friendly tracing and Verifiable Execution so teams can connect agent actions to identity and workflow context.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Agent Security
How should an enterprise prove which AI agent initiated an action?
An enterprise should prove which AI agent initiated an action by assigning the agent a verifiable workload identity and recording the execution path.
- Agent Security
Why is workload identity different from a user account for an agent?
Workload identity identifies software, services, agents, or tools, while a user account identifies a person.
- Agent Security
Where is cryptographic identity useful in agent-to-tool calls?
Cryptographic identity is useful when an agent must prove its identity to a tool or service before access is granted.