What is recorded
- Agent runs and tool activity attached to threads and workflows.
- Action requests, policy decisions, approvals, execution results, and available evidence.
- Administrative changes, plugin activity, and security-relevant events.
- Workflow, watcher, and records-app events needed to trace operational work.
Monitor security logging
If durable security-event logging fails, OpenNeko emits security.audit_logging_failure to stderr and reports the condition through /health/security. The web and worker can also send this condition to a configured webhook.
Route container logs and the optional webhook into monitoring outside the OpenNeko database so a local failure is still visible.