Audit log
Also: 稽核日誌 · 審計日誌 · 操作紀錄 · audit trail
A tamper-evident record of behaviour: when, driven by what input, the agent called which tools with which arguments and got which results — written by the execution layer, not narrated by the model.
When you will meet it
After an incident — data touched, money spent, a wrong report shipped — your only question is what actually happened. "The model said it verified" does not count: this site documented an agent writing verify.done=true into its state file while the session log showed verification never occurred. Only logs written by code, independent of the model's narration, can expose that.
An analogy
Like a dashcam. The driver's "I definitely signalled" and the footage are two kinds of evidence; after a crash, insurers and police watch the footage, not the statement. The agent's narration is the statement; the harness's log is the footage.
Minimal example
不是稽核日誌(模型自述,存在對話裡):
「我已檢查過所有檔案,確認沒有敏感資訊,並完成驗證。」
是稽核日誌(程式寫入,append-only):
14:02:11 tool_call read_file {"path":"data/users.csv"} → ok 4.2KB
14:02:15 tool_call http_post {"url":"api.example.com"} → 403 blocked
14:02:15 gate_decision DENY reason=pii-egress policy=v3
14:03:40 session_end tokens=18233
要件:時間戳、動作、參數、結果、誰批准的;
寫入者不能是被記錄的對象,且事後不可修改。Note the third line: blocked attempts get logged too. A log of only successful actions cannot answer whether something was attempted — and failed attempts are often the earliest signal of an intrusion.
What people get wrong
- Treating the model's narration or the chat transcript as an audit log. A transcript is model-generated text: it can skip, beautify or outright fabricate (this site has the receipts). Audit entries must be written by the tool-executing layer at the moment of the action — recorder separate from the recorded.
- Keeping the logs inside the same writable scope as the system they watch. An agent that can edit its own logs effectively has none; audit records belong outside its write permissions, ideally append-only.