Article chapter 06 of 08
Keep the records support is going to need
When support or a reviewer asks what happened, the logs should be able to answer without every private input being dumped into one place. I'd design the event record around the workflow states and decisions. Each event gets a run identifier, event type, timestamp, actor or service identity, workflow version, target reference, result and a correlation identifier for any external request.
Only keep raw model input and output where the purpose, access and retention period have been approved. For a lot of workflows, structured references plus a redacted output give enough day-to-day visibility, with authorised access to fuller evidence when there's an investigation. Logging everything by default creates a second, badly governed store of sensitive material.
Monitoring should cover runs waiting for review, unknown external actions, source ingestion failures, permission denials, validation failures, tool timeouts and the age of the oldest unresolved item. Model latency on its own won't tell you a queue has stopped moving.
Every alert needs an owner and a response. Write down which conditions page someone, which create a work item and which get looked at on a schedule, and include the link or query that finds the affected runs. An alert that says "AI error rate increased" is hard to do anything with if it doesn't tell you the task family, configuration or stage that failed.
Build a support view before the first broad release. It should let someone find a run by a customer-safe reference, see its current state, list approved actions and show source and tool evidence according to the operator's access. It shouldn't expose hidden prompts or unrelated private data just because support needs to fix one task.
Try the evidence trail on a prepared failure. Ask someone who didn't build the feature to work out what happened and suggest the safe next action. Missing timestamps, vague state names and source links they can't open show up quickly, and you can update the runbook and interface from there.