PLATFORM / Audit Trail

One audit trail. Every agent, every user, every tool.

All agent activity across all your applications lands in one centralized record — both identities, the action, and the verdict.

Get a demoExplore the workflow ↓
01 / IDENTITY02 / POLICY03 / AUDIT
FABRIQ / RIPPLEIDENTITY · PERMISSIONS · VISIBILITY
Every action leaves a thread.FABRIQ / AUDIT
01 / THE CONTEXT

A record the agent
does not write itself.

When an agent misbehaves — or an auditor asks — you need a record you can trust. The agent shouldn’t write its own.

AUTHORITY
agent
∩
person
RESOLVED PER REQUEST
02 / IN PRACTICE

Every action leaves a thread.

THREE RECORDS · ONE TRAILIllustrative · the same schema whatever the verdict
  1. EVT 8f2a·0431
    Google DriveRead an authorized record
    asked by
    Dana Whitfield · Analyst
    acting agent
    review-agent
    call
    drive.read · Q3 board pack
    policy
    Within both grants
    • identity
    • scope
    • policy
    Allowed

    Both identities on the record, and the reason it was allowed sits next to them.

  2. EVT 8f2a·0432
    SalesforceDelete a protected record
    asked by
    Priya Menon · Support
    acting agent
    support-bot
    call
    crm.record.delete · account 4471
    policy
    User has no delete scope
    • identity
    • scope
    • policy
    Blocked

    A refusal is an event too. The trail says which check stopped it, not merely that nothing happened.

  3. EVT 8f2a·0433
    BigQueryExport an audit report
    asked by
    Dana Whitfield · Analyst
    acting agent
    review-agent
    call
    audit.export · last 30 days
    policy
    Awaiting a named approver
    • identity
    • scope
    • policy
    Held

    The wait is on the record from the moment it starts — not only once someone answers.

Illustrative records · the agent does not write these; it is written about.

03 / WHAT CHANGES

Control, in the details.

01

One trail across everything.

Every agent, every user, every connected tool — a single centralized record, one schema.

02

Both identities on every event.

The person who asked and the agent that acted — with tool, action, and timestamp.

03

The verdict is part of the record.

Allowed, held for approval, or refused — outcomes land in the trail.

04

Query and filter in the dashboard.

Slice by service, event type, and time window.

05

Warehouse-grade storage, exportable.

Events land in BigQuery-backed storage and export to your own tooling.

06

Usage metering alongside.

Calls per user and per tool, over time — right beside the audit trail.

THE INDEPENDENT RECORD

Follow the action backward.

Illustrative activity ledger
10:42:08Google Drivedrive.readresearch-agent for Danaallowed

Tool: Google Drive · Agent: research-agent · Acting user: Dana · Policy: Within both grants

Request→Identity resolved→Policy checked→Decision recorded
10:42:04Google Drivedrive.deletesupport-bot for Priyablocked

Tool: Google Drive · Agent: support-bot · Acting user: Priya · Policy: User lacks delete scope

Request→Identity resolved→Policy checked→Decision recorded
10:41:59GitHubgithub.open_prcoding-agent for Alexallowed

Tool: GitHub · Agent: coding-agent · Acting user: Alex · Policy: Branch write permitted

Request→Identity resolved→Policy checked→Decision recorded
10:41:36Slackslack.post_messagesupport-bot for Priyaallowed

Tool: Slack · Agent: support-bot · Acting user: Priya · Policy: Channel within both grants

Request→Identity resolved→Policy checked→Decision recorded
10:41:12Salesforcesalesforce.exportresearch-agent for Danablocked

Tool: Salesforce · Agent: research-agent · Acting user: Dana · Policy: Export not in the agent’s scope

Request→Identity resolved→Policy checked→Decision recorded
THREE LAYERS. ONE DECISION.

The boundary travels with the work.

Explore the context attached to every request.

What is this agent allowed to do?

review-agent has a defined purpose and a bounded set of tools.

QUESTIONS

A closer look.

Is it really one trail across everything?+

Yes. Every agent action against every connected tool lands in the same record — one schema for all users and agents, no per-app log stitching.

Does the agent write its own log?+

No. Logging happens at the policy layer where each call is checked — outside the agent’s reach entirely.

Are refused calls in the trail too?+

Verdicts are part of the record — events show whether a call was allowed, held for approval, or refused, right next to who asked and which agent acted.

Can we export to our own tooling?+

Yes — events live in warehouse-grade storage and export cleanly for your SIEM, warehouse, or audit workflow.

How do we investigate an incident?+

Filter the trail by service, event type, or time window in the dashboard — every event carries both identities and the verdict, so the sequence reconstructs in minutes.

YOUR NEXT CHAPTER

Give your agents
room to move.

See Fabriq in action
Integration HubInternal AgentsCoding Agents