Product feature · security-privacy

Audit logsCommon product term

Record security-relevant activity in an administrative audit log.

Terminology basis: Common product term. xAI — Grok Bot for teams and enterprises

Audit logs: 0 supported, 5 partial, 1 unsupported, 25 unreviewed across 31 cataloged products.

Markdown · JSON

Explore this familyMore in Security and privacy7 capabilities

Current evidence by product

Can my agent use Audit logs?

Read across for the answer. 6 of 31 current product columns have reviewed evidence; unreviewed does not mean unsupported.

  • Supported0
  • Partial5
  • Unsupported1
  • Unknown25
  • Not applicable0

Web

9 products

Desktop

13 products

CLI

9 products

Unknown means no public evidence has been reviewed for that product and capability. It does not mean unsupported.

How statuses are assigned

Definition and scope

What this capability means

This row asks whether security-relevant activity is recorded with enough identity and provenance for investigation. Conversation history is not sufficient when it omits tool parameters, connector reads, file changes, approvals, child-agent actions, model routing, policy decisions, sharing, exports, and administrator changes.

Evidence should record event types and fields, user and service identities, timestamps, model and harness version, retention, search, export or streaming API, SIEM integration, tenant isolation, tamper resistance, redaction, regional placement, and documented gaps.

Traceable compatibility

Assertion ledger

Documentation evidence only. No runtime conformance test is implied.

Grok Botdesktop · current
Unsupported
Target
2026-08-28 Grok Bot desktop documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • runtimespend and usage are visible today; the documented Bot-action audit view is not yet available
Evidence
ChatGPTweb · current
Partial
Target
2026-08-28 ChatGPT Enterprise documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise Compliance API access and appropriate administrator permissions are required
  • runtimesupported append-only compliance records can be collected continuously or downloaded as JSONL for a SIEM, data lake, investigation, retention, or legal-hold workflow
  • policyexact event coverage, schemas, filters, retention, and request mechanics are delegated to the live API reference and are not established by the overview page
Evidence
ChatGPTdesktop · current
Partial
Target
2026-08-28 ChatGPT Enterprise documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise Compliance API access and appropriate administrator permissions are required
  • policycoverage follows the workspace and products represented in the current API reference; this overview does not guarantee every local file, tool, approval, or subagent event
Evidence
Codex CLIcli · current
Partial
Target
2026-08-28 Codex Enterprise documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise Compliance API access and ChatGPT workspace authentication are required; API-key-only Codex use follows separate Platform controls
  • runtimethe overview explicitly supports correlating Codex activity, but the current API reference owns exact local-client event coverage and retention
Evidence
Claudeweb · current
Partial
Target
2026-08-28 Claude Enterprise documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise Owner or Primary Owner access is required; the export aggregates the prior 180 days and its download link remains active for 24 hours
  • runtimelogs include actor, event, entity, IP, device, user-agent, and related fields; chat and project titles and content are excluded and represented by identifiers
  • policyorganizations using customer-managed encryption keys must use Compliance API events instead of the Export logs button
Evidence
Claudedesktop · current
Partial
Target
2026-08-28 Claude Enterprise documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise Owner or Primary Owner access is required; the organization export aggregates the prior 180 days
  • runtimeclient and device metadata may appear when available, but chat content is excluded and the reviewed page does not establish complete local tool, approval, or subagent event coverage
Evidence
  1. 1. Evidence checked 2026-08-28: xAI's Grok Bot team documentation says spend and usage are visible in the dashboard but an audit view of Bot actions is still coming. Conversation transcripts expose activity but do not satisfy this row's exportable security-event audit-log definition.
  2. 2. Evidence checked 2026-08-28: OpenAI's Enterprise Compliance API provides an append-only compliance log stream and JSONL download workflow for supported workspace records, including correlation with Codex activity. The live API reference—not the overview page—owns current event coverage, fields, retention, and permissions.
  3. 3. Evidence checked 2026-08-28: Claude Enterprise Owners can export the previous 180 days of organization audit events with actor, entity, IP, device, user-agent, and event fields. Chat and project content are excluded from audit logs, and customer-managed encryption key organizations use the Compliance API instead of the export button.