Skip to content

Audit log filters, export & integrity

Pro extends the audit log:

The filter bar above the log:

  • Agent — all, “Unknown agents”, or one agent
  • Ability — exact ability name
  • Decision — Allowed, Denied, Needs approval
  • Status — success, blocked, pending approval, error, permission denied, incomplete
  • From / To — date and time

Click Filter to apply and Reset to clear.

Export CSV in the header downloads the entries matching the current filters (up to 50,000 rows) as raqvio-ag-audit-YYYYMMDD-HHMMSS.csv, with these columns:

id, created_at, request_id, agent_name, user_login, channel, ability, risk, decision, reason, status, enforced, duration_ms, result_summary, approval_id, snapshot_id

The redacted input is not included in the export. Values that a spreadsheet could interpret as formulas are neutralised.

With Pro, the audit log is tamper-evident. Every 5 minutes a background job seals new entries. Each seal is a keyed hash (HMAC-SHA256) of the entry and of the seal before it, so the entries form a chain. The key comes from your wp-config.php secrets and is never stored in the database.

Verify integrity in the Audit Log header first seals any waiting entries, then checks the whole chain. It reports:

Result Meaning
No tampering found. N sealed entries checked. Every sealed entry is unchanged and none is missing.
Entry #N was changed after it was sealed. Someone edited the entry in the database.
Entry #N was deleted. The entry is gone, but its seal remains.
Sealed entries just before #N were removed. Entries were deleted together with their seals.
The oldest entries, before #N, were removed outside the normal retention cleanup. Entries were deleted from the start of the log by something other than the daily cleanup.
The newest sealed entries were removed. Entries were deleted from the end of the log.
N entries were added between sealed entries. Rows were inserted into the log after sealing.

The daily retention cleanup is not reported as tampering: Raqvio Agent Guardrails records a signed starting point for the chain after each cleanup.

  • Entries written in the last few minutes are not sealed yet. The result says how many are waiting.
  • Someone who holds your wp-config.php secrets can rebuild the chain.
  • The key is derived from RAQVIO_AG_ENCRYPTION_KEY if you define it in wp-config.php, otherwise from the WordPress security keys. If that key changes, older entries show as changed. Define RAQVIO_AG_ENCRYPTION_KEY once and keep it if you rotate your security keys.

Entry details and the header also give access to rollback.