System audit
The system audit records administrative operations, Agent activity, access denials and retained historical events. It answers who performed which action, on what object, at what time and with what result.

Audit scope
Records are grouped into:
- Administrative operations: Changes to models, enterprise Skills, Tools/MCP, knowledge documents, organization users, position roles, traffic allocation, system settings and admin accounts.
- Agent activity: Activity produced when Agents use platform capabilities and enterprise resources.
- Historical records: Retained audit data preserved for compatibility and lookup.
The page summarizes administrative operations, failures, Agent activity and access denials over the past 24 hours.
Query audit records
Administrators can:
- Search by actor, action or object keyword.
- Filter successful, failed or denied results.
- Filter by model center, enterprise Skills, Tools, knowledge, organization, position roles, traffic allocation and system settings.
- Review time, actor, action, object, source and result.
- Open details for full context and error information.
Failed and denied operations remain visible, helping distinguish insufficient permission, invalid parameters and service failures.
Audit practices
- Review denials and failed operations regularly to identify configuration errors or unexpected behavior.
- Pay particular attention to changes involving models, credentials, enterprise Skills, Tools and access scope.
- After a temporary grant expires or is revoked, use the audit trail to verify the change.
- Restrict audit-data access and retention according to enterprise policy.
