Audit log filters, export & integrity
Pro extends the audit log:
Filters
Section titled “Filters”The filter bar above the log:
- Agent — all, “Unknown agents”, or one agent
- Ability — exact ability name
- Decision — Allowed, Denied, Needs approval
- Status — success, blocked, pending approval, error, permission denied, incomplete
- From / To — date and time
Click Filter to apply and Reset to clear.
Export CSV
Section titled “Export CSV”Export CSV in the header downloads the entries matching the current filters (up to 50,000 rows) as raqvio-ag-audit-YYYYMMDD-HHMMSS.csv, with these columns:
id, created_at, request_id, agent_name, user_login, channel, ability, risk, decision, reason, status, enforced, duration_ms, result_summary, approval_id, snapshot_id
The redacted input is not included in the export. Values that a spreadsheet could interpret as formulas are neutralised.
Verify integrity
Section titled “Verify integrity”With Pro, the audit log is tamper-evident. Every 5 minutes a background job seals new entries. Each seal is a keyed hash (HMAC-SHA256) of the entry and of the seal before it, so the entries form a chain. The key comes from your wp-config.php secrets and is never stored in the database.
Verify integrity in the Audit Log header first seals any waiting entries, then checks the whole chain. It reports:
| Result | Meaning |
|---|---|
| No tampering found. N sealed entries checked. | Every sealed entry is unchanged and none is missing. |
| Entry #N was changed after it was sealed. | Someone edited the entry in the database. |
| Entry #N was deleted. | The entry is gone, but its seal remains. |
| Sealed entries just before #N were removed. | Entries were deleted together with their seals. |
| The oldest entries, before #N, were removed outside the normal retention cleanup. | Entries were deleted from the start of the log by something other than the daily cleanup. |
| The newest sealed entries were removed. | Entries were deleted from the end of the log. |
| N entries were added between sealed entries. | Rows were inserted into the log after sealing. |
The daily retention cleanup is not reported as tampering: Raqvio Agent Guardrails records a signed starting point for the chain after each cleanup.
What it does not protect against
Section titled “What it does not protect against”- Entries written in the last few minutes are not sealed yet. The result says how many are waiting.
- Someone who holds your
wp-config.phpsecrets can rebuild the chain. - The key is derived from
RAQVIO_AG_ENCRYPTION_KEYif you define it inwp-config.php, otherwise from the WordPress security keys. If that key changes, older entries show as changed. DefineRAQVIO_AG_ENCRYPTION_KEYonce and keep it if you rotate your security keys.
Rollback
Section titled “Rollback”Entry details and the header also give access to rollback.