Audit and evidence
What the control plane records about every decision, and what it deliberately does not.
Payload-free by default#
Audit events record decisions, not conversations. An event says which agent was selected, what policy decided and why, which models and tools were involved, and what it cost — without capturing the prompt or the response.
That default is what makes the evidence trail safe to keep for a long time and safe to ship to a shared analytics store. Payload capture is opt-in per policy, not a global switch.
What an event carries#
- Request identity: request ID, tenant, actor, timestamp.
- Routing: the agent selected and the reason.
- Policy: the decision and its reason codes.
- Usage: model, tokens, estimated cost.
- Outcome: success, denial, approval state, or failure.
Emission modes#
Audit runs in off, sync, or async. Asynchronous emission is the usual
production choice: evidence should not add latency to a governed request, and a slow sink should not become an
outage. Synchronous emission is for the case where an unrecorded request is worse than a failed one.
Where it goes#
The default sink writes structured events to stdout, which any cluster log pipeline already collects. The demo observability profile adds a ClickHouse sink and Grafana dashboards so you can query spend and denials directly. See Operations.