{
  "title": "Audit logs",
  "description": "Record security-relevant activity in an administrative audit log.",
  "slug": "audit-logs",
  "locale": "en",
  "seoTitle": "Audit log compatibility — Can My Agent Use",
  "socialTitle": "Audit logs",
  "socialDescription": "Compare documented administrative audit logs and their event coverage.",
  "llmSummary": "Audit logs are product-provided administrative records of security-relevant activity; ordinary conversation history is not automatically an audit log.",
  "audience": "Security operations, compliance, and platform teams.",
  "contentKind": "feature",
  "status": "published",
  "tags": [
    "security",
    "audit",
    "observability",
    "enterprise"
  ],
  "updated": "2026-08-28T00:00:00.000Z",
  "published": "2026-08-28T00:00:00.000Z",
  "category": "security-privacy",
  "summary": "Record security-relevant activity in an administrative audit log.",
  "specLabel": "Common product term",
  "aliases": [
    "activity log",
    "security log",
    "admin audit"
  ],
  "capabilityKind": "atomic",
  "parent": "data-security-controls",
  "related": [
    "admin-policy-controls",
    "subagent-approval-boundaries",
    "conversation-export"
  ],
  "relations": [],
  "highlight": false,
  "notes": [
    {
      "id": 1,
      "text": "Evidence checked 2026-08-28: xAI's Grok Bot team documentation says spend and usage are visible in the dashboard but an audit view of Bot actions is still coming. Conversation transcripts expose activity but do not satisfy this row's exportable security-event audit-log definition."
    },
    {
      "id": 2,
      "text": "Evidence checked 2026-08-28: OpenAI's Enterprise Compliance API provides an append-only compliance log stream and JSONL download workflow for supported workspace records, including correlation with Codex activity. The live API reference—not the overview page—owns current event coverage, fields, retention, and permissions."
    },
    {
      "id": 3,
      "text": "Evidence checked 2026-08-28: Claude Enterprise Owners can export the previous 180 days of organization audit events with actor, entity, IP, device, user-agent, and event fields. Chat and project content are excluded from audit logs, and customer-managed encryption key organizations use the Compliance API instead of the export button."
    }
  ],
  "issues": [],
  "resources": [
    {
      "title": "Methodology",
      "href": "/methodology",
      "kind": "note"
    },
    {
      "id": "xai-grok-bot-team-audit",
      "title": "xAI — Grok Bot for teams and enterprises",
      "href": "https://docs.x.ai/grok-bot/teams-and-enterprises",
      "kind": "docs",
      "publisher": "xAI",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Can I see what Bots did on behalf of my team?"
    },
    {
      "id": "openai-compliance-api",
      "title": "OpenAI — Compliance API and audit events",
      "href": "https://learn.chatgpt.com/docs/enterprise/compliance-api",
      "kind": "docs",
      "publisher": "OpenAI",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "When to use the Compliance API; download logs; administration boundaries"
    },
    {
      "id": "anthropic-audit-logs",
      "title": "Anthropic Help Center — Access audit logs",
      "href": "https://support.claude.com/en/articles/9970975-access-audit-logs",
      "kind": "docs",
      "publisher": "Anthropic",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Export logs; log structure; recorded events"
    }
  ],
  "support": [
    {
      "harness": "grok-bot-desktop",
      "versions": [
        {
          "track": "current",
          "status": "no",
          "noteIds": [
            1
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Grok Bot desktop documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "runtime",
              "value": "spend and usage are visible today; the documented Bot-action audit view is not yet available"
            }
          ],
          "evidence": [
            {
              "resourceId": "xai-grok-bot-team-audit",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ],
          "stage": "planned"
        }
      ]
    },
    {
      "harness": "chatgpt-web",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            2
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 ChatGPT Enterprise documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "Enterprise Compliance API access and appropriate administrator permissions are required"
            },
            {
              "type": "runtime",
              "value": "supported append-only compliance records can be collected continuously or downloaded as JSONL for a SIEM, data lake, investigation, retention, or legal-hold workflow"
            },
            {
              "type": "policy",
              "value": "exact event coverage, schemas, filters, retention, and request mechanics are delegated to the live API reference and are not established by the overview page"
            }
          ],
          "evidence": [
            {
              "resourceId": "openai-compliance-api",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "chatgpt-desktop",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            2
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 ChatGPT Enterprise documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "Enterprise Compliance API access and appropriate administrator permissions are required"
            },
            {
              "type": "policy",
              "value": "coverage follows the workspace and products represented in the current API reference; this overview does not guarantee every local file, tool, approval, or subagent event"
            }
          ],
          "evidence": [
            {
              "resourceId": "openai-compliance-api",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "codex-cli",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            2
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Codex Enterprise documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "Enterprise Compliance API access and ChatGPT workspace authentication are required; API-key-only Codex use follows separate Platform controls"
            },
            {
              "type": "runtime",
              "value": "the overview explicitly supports correlating Codex activity, but the current API reference owns exact local-client event coverage and retention"
            }
          ],
          "evidence": [
            {
              "resourceId": "openai-compliance-api",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "claude-web",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            3
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Claude Enterprise documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "Enterprise Owner or Primary Owner access is required; the export aggregates the prior 180 days and its download link remains active for 24 hours"
            },
            {
              "type": "runtime",
              "value": "logs include actor, event, entity, IP, device, user-agent, and related fields; chat and project titles and content are excluded and represented by identifiers"
            },
            {
              "type": "policy",
              "value": "organizations using customer-managed encryption keys must use Compliance API events instead of the Export logs button"
            }
          ],
          "evidence": [
            {
              "resourceId": "anthropic-audit-logs",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "claude-desktop",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            3
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Claude Enterprise documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "Enterprise Owner or Primary Owner access is required; the organization export aggregates the prior 180 days"
            },
            {
              "type": "runtime",
              "value": "client and device metadata may appear when available, but chat content is excluded and the reviewed page does not establish complete local tool, approval, or subagent event coverage"
            }
          ],
          "evidence": [
            {
              "resourceId": "anthropic-audit-logs",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    }
  ],
  "html": "/features/audit-logs",
  "markdown": "/features/audit-logs.md",
  "json": "/api/v1/features/audit-logs.json",
  "body": "This row asks whether security-relevant activity is recorded with enough identity and provenance for investigation. Conversation history is not sufficient when it omits tool parameters, connector reads, file changes, approvals, child-agent actions, model routing, policy decisions, sharing, exports, and administrator changes.\n\nEvidence should record event types and fields, user and service identities, timestamps, model and harness version, retention, search, export or streaming API, SIEM integration, tenant isolation, tamper resistance, redaction, regional placement, and documented gaps."
}