Agent Audit Logging: What to Record and What to Redact
When an agent does something surprising, the log is the only account of what happened. What a usable agent audit record contains, and what it must not.
ReadPractical writing for developers building with large language models — how they work, how to pick one, and how to keep the bill predictable.
Agents, tool calling, and the loop that makes them useful.
When an agent does something surprising, the log is the only account of what happened. What a usable agent audit record contains, and what it must not.
ReadAgents resend the whole transcript every turn and re-read the same files repeatedly. Three caching layers fix that, and each has different keying rules.
ReadLong agent runs die halfway. What to checkpoint, where the boundaries belong, and why external side effects break the snapshot model entirely.
ReadUnbounded agent spawning turns a fast run into a retry storm. Worker pools, semaphores, resource locks and the fairness problem nobody plans for.
ReadAgents fail in about eight recognisable ways, and each one needs a different fix. A field guide to spotting them from a trace and knowing what to change.
ReadFan-out looks free until the orchestrator stops reading results properly. The four ceilings that cap parallel agents, and how to find yours before production does.
ReadThe filesystem is an agent's most consequential tool surface. Path containment, read and write asymmetry, and why files are an injection vector.
ReadEvery handoff between agents is a compression step. Four patterns for transferring control, what each one drops, and how to build a handoff packet.
ReadEvery coding agent is the same short loop. Understanding its structure tells you where they fail and which parts are worth engineering.
ReadAn agent with a shell and open network egress can exfiltrate anything it can read. How to scope outbound access without breaking the toolchain.
ReadAverages hide every interesting agent failure. Which counters and histograms to define, what to use as the denominator, and how to alert without drowning in noise.
ReadPer-call prompts, session grants, capability scoping and policy engines. How the main agent permission models behave once real work runs through them.
ReadShowing 1–12 of 74 articles