---
title: "Audit logs"
canonical: "https://canmyagentuse.com/features/audit-logs"
contentKind: "feature"
locale: "en"
description: "Record security-relevant activity in an administrative audit log."
llmSummary: "Audit logs are product-provided administrative records of security-relevant activity; ordinary conversation history is not automatically an audit log."
publishedAt: "2026-08-28T00:00:00.000Z"
updatedAt: "2026-08-28T00:00:00.000Z"
verifiedAt: "2026-08-28"
tags: ["security","audit","observability","enterprise"]
---

# Audit logs

Audit logs are product-provided administrative records of security-relevant activity; ordinary conversation history is not automatically an audit log.

- HTML: https://canmyagentuse.com/features/audit-logs
- JSON: https://canmyagentuse.com/api/v1/features/audit-logs.json
- Markdown: https://canmyagentuse.com/features/audit-logs.md

Terminology basis: **Common product term** — https://docs.x.ai/grok-bot/teams-and-enterprises.

## Current support at a glance

Audit logs: 0 supported, 5 partial, 1 unsupported, 25 unreviewed across 31 cataloged products.

- Reviewed current products: 6 of 31
- Supported: 0
- Partial: 5
- Unsupported: 1
- Unreviewed: 25
- Not applicable: 0

Unknown or unreviewed means insufficient published evidence; it does not mean unsupported.

This row asks whether security-relevant activity is recorded with enough identity and provenance for investigation. Conversation history is not sufficient when it omits tool parameters, connector reads, file changes, approvals, child-agent actions, model routing, policy decisions, sharing, exports, and administrator changes.

Evidence should record event types and fields, user and service identities, timestamps, model and harness version, retention, search, export or streaming API, SIEM integration, tenant isolation, tamper resistance, redaction, regional placement, and documented gaps.

## Catalog context

- Category: [security-privacy](/categories/security-privacy.md)
- Terminology basis: Common product term
- Aliases: activity log, security log, admin audit
- Family: [Security and privacy](/features/data-security-controls.md)
- Siblings: [Data residency](/features/data-residency.md), [Data retention controls](/features/data-retention-controls.md), [Encryption key management](/features/encryption-key-controls.md), [Offline operation](/features/local-only-mode.md), [Organization policy controls](/features/admin-policy-controls.md), [Secrets management](/features/secrets-management.md), [Training data controls](/features/training-data-controls.md)

## Compatibility assertions

Unknown means insufficient published evidence; it does not mean unsupported.

### ChatGPT (web)

- Harness: [ChatGPT](/harnesses/chatgpt-web.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 ChatGPT Enterprise documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise Compliance API access and appropriate administrator permissions are required
  - Constraint (runtime): supported append-only compliance records can be collected continuously or downloaded as JSONL for a SIEM, data lake, investigation, retention, or legal-hold workflow
  - Constraint (policy): exact event coverage, schemas, filters, retention, and request mechanics are delegated to the live API reference and are not established by the overview page
  - Evidence: [OpenAI — Compliance API and audit events](https://learn.chatgpt.com/docs/enterprise/compliance-api) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: OpenAI's Enterprise Compliance API provides an append-only compliance log stream and JSONL download workflow for supported workspace records, including correlation with Codex activity. The live API reference—not the overview page—owns current event coverage, fields, retention, and permissions.
- preview: **Unknown**

### Claude (web)

- Harness: [Claude](/harnesses/claude-web.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 Claude Enterprise documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise Owner or Primary Owner access is required; the export aggregates the prior 180 days and its download link remains active for 24 hours
  - Constraint (runtime): logs include actor, event, entity, IP, device, user-agent, and related fields; chat and project titles and content are excluded and represented by identifiers
  - Constraint (policy): organizations using customer-managed encryption keys must use Compliance API events instead of the Export logs button
  - Evidence: [Anthropic Help Center — Access audit logs](https://support.claude.com/en/articles/9970975-access-audit-logs) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: Claude Enterprise Owners can export the previous 180 days of organization audit events with actor, entity, IP, device, user-agent, and event fields. Chat and project content are excluded from audit logs, and customer-managed encryption key organizations use the Compliance API instead of the export button.
- preview: **Unknown**

### Gemini (web)

- Harness: [Gemini](/harnesses/gemini-web.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot (web)

- Harness: [Copilot](/harnesses/copilot-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok (web)

- Harness: [Grok](/harnesses/grok-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok Bot (desktop)

- Harness: [Grok Bot](/harnesses/grok-bot-desktop.md)
- current: **Unsupported**
  - Target: hosted-observation — 2026-08-28 Grok Bot desktop documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (runtime): spend and usage are visible today; the documented Bot-action audit view is not yet available
  - Evidence: [xAI — Grok Bot for teams and enterprises](https://docs.x.ai/grok-bot/teams-and-enterprises) — documented; observed 2026-08-28
  - Qualification note 1: Evidence checked 2026-08-28: xAI's Grok Bot team documentation says spend and usage are visible in the dashboard but an audit view of Bot actions is still coming. Conversation transcripts expose activity but do not satisfy this row's exportable security-event audit-log definition.

### Perplexity (web)

- Harness: [Perplexity](/harnesses/perplexity-web.md)
- current: **Unknown**
- preview: **Unknown**

### Le Chat (web)

- Harness: [Le Chat](/harnesses/le-chat.md)
- current: **Unknown**
- preview: **Unknown**

### Devin (web)

- Harness: [Devin](/harnesses/devin-web.md)
- current: **Unknown**
- preview: **Unknown**

### Replit Agent (web)

- Harness: [Replit Agent](/harnesses/replit-agent.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT (desktop)

- Harness: [ChatGPT](/harnesses/chatgpt-desktop.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 ChatGPT Enterprise documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise Compliance API access and appropriate administrator permissions are required
  - Constraint (policy): coverage follows the workspace and products represented in the current API reference; this overview does not guarantee every local file, tool, approval, or subagent event
  - Evidence: [OpenAI — Compliance API and audit events](https://learn.chatgpt.com/docs/enterprise/compliance-api) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: OpenAI's Enterprise Compliance API provides an append-only compliance log stream and JSONL download workflow for supported workspace records, including correlation with Codex activity. The live API reference—not the overview page—owns current event coverage, fields, retention, and permissions.
- preview: **Unknown**

### Claude (desktop)

- Harness: [Claude](/harnesses/claude-desktop.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 Claude Enterprise documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise Owner or Primary Owner access is required; the organization export aggregates the prior 180 days
  - Constraint (runtime): client and device metadata may appear when available, but chat content is excluded and the reviewed page does not establish complete local tool, approval, or subagent event coverage
  - Evidence: [Anthropic Help Center — Access audit logs](https://support.claude.com/en/articles/9970975-access-audit-logs) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: Claude Enterprise Owners can export the previous 180 days of organization audit events with actor, entity, IP, device, user-agent, and event fields. Chat and project content are excluded from audit logs, and customer-managed encryption key organizations use the Compliance API instead of the export button.
- preview: **Unknown**

### Cursor (desktop)

- Harness: [Cursor](/harnesses/cursor.md)
- current: **Unknown**
- preview: **Unknown**

### OpenWork Desktop (desktop)

- Harness: [OpenWork Desktop](/harnesses/openwork-desktop.md)
- current: **Unknown**

### Copilot Chat (desktop)

- Harness: [Copilot Chat](/harnesses/vscode-copilot.md)
- current: **Unknown**
- preview: **Unknown**

### Chrome WebMCP origin trial (desktop)

- Harness: [Chrome WebMCP origin trial](/harnesses/chrome-webmcp-preview.md)
- current: **Unknown**

### Windsurf (desktop)

- Harness: [Windsurf](/harnesses/windsurf.md)
- current: **Unknown**
- preview: **Unknown**

### Zed Agent (desktop)

- Harness: [Zed Agent](/harnesses/zed-agent.md)
- current: **Unknown**
- preview: **Unknown**

### Continue (desktop)

- Harness: [Continue](/harnesses/continue.md)
- current: **Unknown**
- preview: **Unknown**

### Cline (desktop)

- Harness: [Cline](/harnesses/cline.md)
- current: **Unknown**
- preview: **Unknown**

### JetBrains AI (desktop)

- Harness: [JetBrains AI](/harnesses/jetbrains-ai.md)
- current: **Unknown**
- preview: **Unknown**

### Warp (desktop)

- Harness: [Warp](/harnesses/warp.md)
- current: **Unknown**
- preview: **Unknown**

### Claude CLI (cli)

- Harness: [Claude CLI](/harnesses/claude-cli.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT CLI (cli)

- Harness: [ChatGPT CLI](/harnesses/chatgpt-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Codex CLI (cli)

- Harness: [Codex CLI](/harnesses/codex-cli.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 Codex Enterprise documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise Compliance API access and ChatGPT workspace authentication are required; API-key-only Codex use follows separate Platform controls
  - Constraint (runtime): the overview explicitly supports correlating Codex activity, but the current API reference owns exact local-client event coverage and retention
  - Evidence: [OpenAI — Compliance API and audit events](https://learn.chatgpt.com/docs/enterprise/compliance-api) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: OpenAI's Enterprise Compliance API provides an append-only compliance log stream and JSONL download workflow for supported workspace records, including correlation with Codex activity. The live API reference—not the overview page—owns current event coverage, fields, retention, and permissions.
- preview: **Unknown**

### OpenCode (cli)

- Harness: [OpenCode](/harnesses/opencode.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini CLI (cli)

- Harness: [Gemini CLI](/harnesses/gemini-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Aider (cli)

- Harness: [Aider](/harnesses/aider.md)
- current: **Unknown**
- preview: **Unknown**

### Goose (cli)

- Harness: [Goose](/harnesses/goose.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot CLI (cli)

- Harness: [Copilot CLI](/harnesses/copilot-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Amp (cli)

- Harness: [Amp](/harnesses/amp-cli.md)
- current: **Unknown**
- preview: **Unknown**
