One trail across everything.
Every agent, every user, every connected tool — a single centralized record, one schema.
All agent activity across all your applications lands in one centralized record — both identities, the action, and the verdict.
When an agent misbehaves — or an auditor asks — you need a record you can trust. The agent shouldn’t write its own.
EVT 8f2a·0431Both identities on the record, and the reason it was allowed sits next to them.
EVT 8f2a·0432A refusal is an event too. The trail says which check stopped it, not merely that nothing happened.
EVT 8f2a·0433The wait is on the record from the moment it starts — not only once someone answers.
Illustrative records · the agent does not write these; it is written about.
Every agent, every user, every connected tool — a single centralized record, one schema.
The person who asked and the agent that acted — with tool, action, and timestamp.
Allowed, held for approval, or refused — outcomes land in the trail.
Slice by service, event type, and time window.
Events land in BigQuery-backed storage and export to your own tooling.
Calls per user and per tool, over time — right beside the audit trail.
10:42:08Tool: Google Drive · Agent: research-agent · Acting user: Dana · Policy: Within both grants
10:42:04Tool: Google Drive · Agent: support-bot · Acting user: Priya · Policy: User lacks delete scope
10:41:59Tool: GitHub · Agent: coding-agent · Acting user: Alex · Policy: Branch write permitted
10:41:36Tool: Slack · Agent: support-bot · Acting user: Priya · Policy: Channel within both grants
10:41:12Tool: Salesforce · Agent: research-agent · Acting user: Dana · Policy: Export not in the agent’s scope
Explore the context attached to every request.
review-agent has a defined purpose and a bounded set of tools.
The request acts for analyst, using that person’s permissions.
The policy applies to the requested action within Activity ledger, before the tool executes.
Yes. Every agent action against every connected tool lands in the same record — one schema for all users and agents, no per-app log stitching.
No. Logging happens at the policy layer where each call is checked — outside the agent’s reach entirely.
Verdicts are part of the record — events show whether a call was allowed, held for approval, or refused, right next to who asked and which agent acted.
Yes — events live in warehouse-grade storage and export cleanly for your SIEM, warehouse, or audit workflow.
Filter the trail by service, event type, or time window in the dashboard — every event carries both identities and the verdict, so the sequence reconstructs in minutes.