Logs and Auditing

Know what every agent did, as whom, and what it cost. Archestra logs every model request, tool call, and admin change, from Chat, messaging channels, and connected clients. You do not turn anything on.

Open Logs in the sidebar to answer questions such as:

  • Which agent deleted that Jira ticket, and whose account did it use?
  • Why did the bill jump on Tuesday?
  • Who gave this team admin rights, and what did the role look like before?
  • Why did Guardrails block that call?

What Gets Logged

TabOne row perOpen a row for
LLM ProxySession: agent, model, tokens, spendThe whole conversation. Export JSON saves it.
MCP GatewayTool call: tool, gateway, account used, resultThe arguments and the full result
AuditChange: who, what, when, and if it succeededThe values before and after, the source IP, and any admin acting as someone else
Guardrail consultsGuardrails decision: tool, outcomeWhy the call was allowed or blocked

Who Can Read Them

One permission shows your own logs. An admin permission shows everyone's. The audit log has no "own" view.

TabYour ownEveryone's
LLM Proxy, MCP Gatewaylog:readlog:admin
Guardrail consultsopenappaDiagnostics:readopenappaDiagnostics:admin
AuditauditLog:read

Sharing an agent or a gateway with someone does not let them read its logs.

What to Know