Audit log
Agent Guardrails → Audit Log records every governed ability execution, with redacted input. Entries are stored in your own database.
The list
Section titled “The list”Columns: When, Agent, Channel (mcp, rest, internal), Ability, Risk, Decision (Allowed, Denied, Needs approval), Status and Details; 25 entries per page.
Details opens “Audit entry #N”: when, agent (and WordPress user), channel, ability and risk, decision, reason, status, result summary, duration in milliseconds, request ID, related approval, and Input (redacted).
Agents show as their name, “Unknown agent”, “(deleted agent)”, or “Administrator” for configuration changes.
Statuses
Section titled “Statuses”| Status | Meaning |
|---|---|
| success | Ran and succeeded |
| error | Ran and returned an error |
| blocked | Denied by Raqvio Agent Guardrails |
| pending_approval | Waiting in Approvals (Pro) |
| permission_denied | Refused by the ability’s own WordPress permission check (the user lacks the capability) |
| invalid_input / invalid_output | Rejected by the ability’s input or output schema |
| short_circuited | Another plugin stopped the call after Raqvio Agent Guardrails allowed it |
| incomplete | Still running when the request ended |
Configuration changes
Section titled “Configuration changes”Administrator actions in Raqvio Agent Guardrails are logged too, under raqvio-ag-admin/…: kill switch toggles, agents saved or deleted, permissions, ability overrides, settings (changed keys only; the Slack webhook as “[changed]”), and with Pro rules, approval decisions, rollbacks and fixer changes.
Redaction
Section titled “Redaction”Input is redacted before it is stored:
- Removed (
[redacted]): values whose field name contains password, passwd, token, secret, key, card, cvv, cvc, iban, authorization or cookie, plus any extra keys you add in Settings → Audit & privacy → Extra keys to redact. - Masked: fields named like email (
j***@example.com), phone (last two digits), and address, postcode, zip (first three characters). Email addresses inside any text are masked too. - Abilities marked Never log input on the Abilities screen store no input at all.
- Very large input (over 16 KB) is replaced by a size note.
Redaction works on field names. A card number sent in a field called note would not be recognised as a card number — mark such abilities as “Never log input”, or add the field name to the extra keys.
Retention
Section titled “Retention”You choose how long entries are kept in Settings → Audit log retention (days, 1–365). The default is 30 days, and there is no limit on the number of entries. A daily background job deletes older entries, together with old snapshots and counters.
With Pro you also get filters, CSV export, integrity verification and rollback.