Article chapter 07 of 09
Protecting the trail and the people in it
Audit records can hold private object references, task text, error details and action payloads. Access should be scoped by role and purpose, with tighter handling for full content than for operational metadata.
Redact when the event is created, using structure. Tool schemas can mark credential, personal and high-sensitivity fields so the gateway drops or tokenises them before anything gets logged. A general regular expression run later can miss secrets that only make sense in context, or strip out details you need for recovery.
Don't log raw access tokens, session cookies, secret headers or full connection strings. Store a secret reference or the credential identity instead. If a tool accidentally returns a credential, the event pipeline should quarantine that payload and alert the responsible operator before it spreads into search indexes.
Protect integrity with append-only storage controls and a small set of identities allowed to write. Corrections should be new events that reference the wrong one. If your store can't enforce immutability, database permissions, versioned rows and independent backups still make silent changes harder.
Retention should depend on what's in the event and what you're obliged to keep. Task metadata might need a different period from copied prompt text or source snippets. Record deletions and legal holds as administrative events, and when a deletion is for privacy reasons, make sure it reaches indexes, caches and exported copies where required.
Keep operational search separate from bulk export. Someone allowed to look at one task doesn't automatically need a downloadable dataset of every task. And keep an eye on unusual access to the audit log itself, since it's effectively a map of sensitive activity.
Test redaction against real tool payload shapes and failure messages. Error objects often include request bodies, file paths or provider headers that the success path never shows you.