Security & governance · Glossary term
What is Audit Log?
A durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it happened, and the resulting status.
Why does Audit Log matter?
Consequential agent actions need evidence that supports investigation, policy review, and responsibility beyond performance debugging.
Audit Log in practice
Record tool authorization, approval decisions, external writes, policy versions, and artifact identifiers while redacting secrets and restricting log access.
What is the common confusion about Audit Log?
A trace helps diagnose one execution path. An audit log preserves events required for accountability across executions and over time.
Learn Audit Log in the course
Lessons that name Audit Log in a title or section
- Security — Secrets, API Key Rotation, Audit Logs, Guardrails
Eliminate secret sprawl via centralized vaults (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault). Never store credentials in config files, env files in VCS, spreadsheets.
Covered in Phase 17: Infrastructure & Production.
Related terms
- TraceA correlated record of one request or task across model calls, retrieval, tools, state transitions, retries, approvals, and evaluations.
- ObservabilityThe ability to understand an AI system's behavior from recorded inputs, outputs, state transitions, tool calls, timings, costs, errors,…
- Approval GateA control point that blocks a consequential action until an authorized person or policy grants permission.
- Provenance AttestationAuthenticated, machine-readable metadata that binds an artifact to claims about how, where, when, and from which inputs it was produced.
- Content ProvenanceVerifiable information about the origin and editing history of a piece of media or other digital content, including the actors, tools,…
- Data ClassificationAssigning data to documented sensitivity or impact classes so handling, access, retention, sharing, and incident rules follow the…
- Data ExfiltrationUnauthorized transfer of protected data from a system or trust zone to a person, tool, service, or storage location that is not permitted…
- Data LineageA record of how a data artifact was derived across sources, transformations, joins, filters, versions, and downstream uses.
- Incident ResponseThe coordinated process for detecting, analyzing, containing, recovering from, communicating, and learning from an event that threatens…
- PostmortemA durable incident record that explains impact, detection, response, contributing conditions, recovery, and owned follow-up actions…
- Purpose LimitationFor personal data, collecting and using it only for specified, explicit purposes unless a new use has an appropriate compatible or…
- Separation of DutiesDividing conflicting responsibilities or authority across independent roles so one principal cannot complete a high-risk action without…
- Software Bill of Materials (SBOM)A structured inventory of software components and relationships associated with a product or artifact, often including versions,…
- Zero TrustA security model that grants no implicit trust from network location or asset ownership and instead evaluates each access request against…
Sources
More terms in Security & governance
- AI Risk Assessment
- Content Provenance
- Data Classification
- Data Exfiltration
- Data Lineage
- Data Minimization
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Membership Inference
- Provenance Attestation
- Purpose Limitation
- Red Teaming
- Separation of Duties
- Software Bill of Materials (SBOM)
- Threat Model
- Trust Boundary
- Zero Trust
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.