DocumentationAudit and evidence
Docs/Secure and govern

Audit and evidence

Review decisions, actions, security events, and the limits of the evidence kept inside one deployment.

What is recorded

  • Agent runs and tool activity attached to threads and workflows.
  • Action requests, policy decisions, approvals, execution results, and available evidence.
  • Administrative changes, plugin activity, and security-relevant events.
  • Workflow, watcher, and records-app events needed to trace operational work.

Monitor security logging

If durable security-event logging fails, OpenNeko emits security.audit_logging_failure to stderr and reports the condition through /health/security. The web and worker can also send this condition to a configured webhook.

Route container logs and the optional webhook into monitoring outside the OpenNeko database so a local failure is still visible.

Keep an external copy