Audit & Compliance
81% deployed. 14% governed. Log every tool call.
Every MCP and REST invocation writes an audit record — team-scoped, trace-linked, exportable. Minimum bar for production agents in 2026.
The pain
Agent adoption outpaced security approval. Without per-tool audit, you can't answer: who fetched what, when, at what token cost — for compliance or incident response.
1
Automatic logging
Every tool call → PostgreSQL audit_logs: team_id, request_id, tool, params, token_used, latency_ms, success.
2
Trace & query
/api/v1/audit/trace + Dashboard Activity Logs — filter by tool, time, team.
3
Export
GET /api/v1/audit/export for compliance workflows.
Retention by plan
| Plan | Activity log retention |
|---|---|
| Free | 7 days |
| Pro | 30 days |
| Teams | 90 days |
| Enterprise | 180 days |
SSOT: plan-catalog.ts · marketing reads catalog at build/render time
Before / after
| Scenario | Before | With SmartGate |
|---|---|---|
| Agent actions | Invisible tool calls | Full tool + params audit |
| Compress savings | Unprovable | token_saved in audit for context_gate |
| Multi-tenant | Shared logs risk | team_id isolation on every query |
Activity Logs · mock
| Time | Tool | Tokens | Status |
|---|---|---|---|
| 10:42:01 | smart_context_gate | 1,240 → 496 | saved 744 |
| 10:41:58 | smart_fetch | 8,102 | ok |
| 10:41:55 | smart_search | 412 | ok |