Audit Objects
Audit records usually contain:- requestId or taskId.
- traceId.
- tenantId and organizationId.
- resourceId.
- actorType and actorId.
- toolName or actionTypeCode.
- mappingVersion.
- snapshotId.
- status.
- policyDecision.
- decisionSummary.
- evidenceRef.
- input.
- output.
- duration and timestamp.
Audit Entry Points
Users can access audits through:- The execution audit page, filtered by status, resource, or time.
getAuditTrace, used to review one task flow by taskId.- auditRef in approval requests, linking to related execution records.
- Workbench artifacts, used to review execution effects and visualizations.
Evidence References
The evidenceRef in audit records stores structured evidence summaries, such as:- Number of matched entities.
- graphVersion.
- allowed actions.
- denied actions.
- policyId.
- approvalRequestId.
- snapshotId.
- rowCount or result summary.
Audit and Governance Loop
Audit results can improve governance:- If Agents often hit non-unique entities, add aliases or narrow resource scope.
- If certain actions are frequently denied, check whether policies are too strict or documentation is misleading.
- If queries time out, adjust adapter timeout, cache, or sync granularity.
- If write action approval information is insufficient, require expected effect or more detailed parameters.
Best Practices
- Pass a stable taskId for each Agent task.
- Reuse the same taskId across multi-step flows to make tracing easier.
- Record audits for low-risk queries too, so users can review answer sources.
- Keep approval requests and policy hit reasons for high-risk actions.
- Do not store tokens, passwords, cookies, or full sensitive business data in audits.
Web Operation Path
Open Governance → Execution Audit and filter by resource, status, time, or task ID. Open a record and check the tool/action, actor, resource, snapshot, policy decision, status, evidence references, and result summary. An approval’sauditRef should return to the same execution chain.
Success signal: A single execution connects discovery, simulation, policy, approval when applicable, and execution, with a final state.
Checklist
- The audit record includes the caller and organization context.
- It references the actual snapshot or graph version.
- The policy allow, deny, or approval reason is explainable.
- Results contain only summaries or artifact references, without credentials or complete sensitive data.