25 September 2025 / Applied AI / 9 chapters

Record inputs without copying everything

From Designing an audit trail for tool-using agents

The audit trail needs to identify the context used, but copying every prompt, document and private record into a general logging platform creates a second uncontrolled content store.

For the task request, store a redacted or access-controlled version of the user instruction, plus a hash of the exact original where integrity checking is required. Record attachments by object ID, version, checksum, classification and the bounded portion extracted. Keep the original in its existing controlled repository.

System instructions and tool definitions should be versioned artefacts. An event can record instruction_version, tool_registry_version, model identifier and relevant runtime settings. If instructions are assembled dynamically, retain the component versions and a hash of the rendered input. Store the full rendered prompt only where policy permits and a real review case requires it.

Retrieval events should identify which source objects were returned, their versions, access decision and whether results were truncated. If a document contributed only two passages, record their stable locations rather than reproducing the whole file.

Make source authority visible. A current system record, an uploaded document and an unverified web page should not appear identical in the log. The event can carry source type, owner, effective date and retrieval method without asking the model to describe those details later.

Input events also need an untrusted-content marker. Tool outputs, files and web pages may contain text that resembles an instruction. Recording that classification helps a reviewer distinguish authorised instructions from source material the agent happened to read.

When an input is unavailable due to permissions, timeout or parse failure, log that fact. A final answer may look complete even though a source named in the task never entered the context.

All articles