Logs and Auditing
Know what every agent did, as whom, and what it cost. Archestra logs every model request, tool call, and admin change, from Chat, messaging channels, and connected clients. You do not turn anything on.
Open Logs in the sidebar to answer questions such as:
- Which agent deleted that Jira ticket, and whose account did it use?
- Why did the bill jump on Tuesday?
- Who gave this team admin rights, and what did the role look like before?
- Why did Guardrails block that call?
What Gets Logged
| Tab | One row per | Open a row for |
|---|---|---|
| LLM Proxy | Session: agent, model, tokens, spend | The whole conversation. Export JSON saves it. |
| MCP Gateway | Tool call: tool, gateway, account used, result | The arguments and the full result |
| Audit | Change: who, what, when, and if it succeeded | The values before and after, the source IP, and any admin acting as someone else |
| Guardrail consults | Guardrails decision: tool, outcome | Why the call was allowed or blocked |
Who Can Read Them
One permission shows your own logs. An admin permission shows everyone's. The audit log has no "own" view.
| Tab | Your own | Everyone's |
|---|---|---|
| LLM Proxy, MCP Gateway | log:read | log:admin |
| Guardrail consults | openappaDiagnostics:read | openappaDiagnostics:admin |
| Audit | auditLog:read |
Sharing an agent or a gateway with someone does not let them read its logs.
What to Know
- Logs stay forever by default. To delete old records, set a retention window. Retention is an Enterprise feature. See Data Retention.
- Behind a load balancer, set
ARCHESTRA_TRUST_PROXY. Otherwise audit records show the load balancer's IP, not the client's. - To send data to your own tools, use metrics and traces.