{"title":"Agent Audit Trails: Which Records Are Outside the Agent’s Reach?","description":"A visible transcript is not necessarily an independently preserved audit record. Capture location, recording defaults, coverage, deletion paths and export timing determine what an operator may be able to reconstruct.","dataset_id":"spd:agent-audit-trails-which-records-are-outside-the-agent-s-reach-f30f7187","canonical_url":"https://superpowerdaily.com/research/agent-audit-trails-which-records-are-outside-the-agent-s-reach-f30f7187","version_url":"https://superpowerdaily.com/research/agent-audit-trails-which-records-are-outside-the-agent-s-reach-f30f7187/versions/v1","version":"v1","snapshot_hash":"3e8827f7ed7e4d1c7cbe73789fbf8a5ad364dedace3c5c85802a709f2aed9c53","date_created":"2026-09-27T17:13:52.364Z","date_modified":"2026-09-27T17:13:52.364Z","license":{"name":"Superpower Daily data reuse terms","url":"https://superpowerdaily.com/terms"},"license_url":"https://superpowerdaily.com/terms","temporal_coverage":"2026-09-27","coverage_note":"Evidence and documentation descriptions are frozen at the supplied collection cutoff, September 27, 2026, 15:30:50 UTC. This is a synthesis of saved sources, not a new documentation collection, configuration review or tampering experiment.","measurement_technique":["Evidence matrix plan: use separate rows for Claude Code local transcripts, eligible Claude Enterprise Compliance API transcripts, the Compliance Activity Feed, Claude Code OpenTelemetry export, OpenAI Agents SDK tracing, Grok Bot Enterprise audit logs, Grok Bot Action Recording and its optional customer export. Columns: recorded content, capture location, default state, eligibility, destination, retention or deletion, coverage gaps and documented tamper-resistance mechanism.","Claude Code local transcripts: plaintext conversation and tool records under ~/.claude/projects; default cleanup after 30 days, with options to skip persistence or purge project records. Whether an agent can delete a particular deployment’s files depends on its permissions.","Eligible Claude Enterprise local sessions: Anthropic captures API-visible exchanges server-side; Compliance API retrieval endpoints are read-only. Default retention is six years, subject to organization retention settings and documented eligibility exclusions. This is not a record of all device activity.","Anthropic’s Compliance Activity Feed starts when enabled, is not backfilled and records administrative and resource activity rather than session content. Configured Claude Code OpenTelemetry delivery is another, customer-collector path; prompt and tool-detail capture require separate settings.","OpenAI Agents SDK: tracing is on by default for eligible organizations and its client-side batch processor exports to OpenAI. Application code can disable tracing or add or replace processors for customer export; tracing is unavailable under ZDR. Do not extend this SDK documentation to every product called an Agents API.","Grok Bot Enterprise: administrative audit logs are not action traces. Action Recording is separately enabled, stores sanitized action categories in an internal store for 90 days, and requires additional configuration for OpenTelemetry export to a customer collector. Recorded actions do not appear on the Audit Log page.","Classify a boundary as documented only where the supplied source describes its mechanism; otherwise mark tamper resistance not established. Treat the paper’s tested harnesses as context, not as a test of these provider-held or customer-held records."],"methodology":["Evidence matrix plan: use separate rows for Claude Code local transcripts, eligible Claude Enterprise Compliance API transcripts, the Compliance Activity Feed, Claude Code OpenTelemetry export, OpenAI Agents SDK tracing, Grok Bot Enterprise audit logs, Grok Bot Action Recording and its optional customer export. Columns: recorded content, capture location, default state, eligibility, destination, retention or deletion, coverage gaps and documented tamper-resistance mechanism.","Claude Code local transcripts: plaintext conversation and tool records under ~/.claude/projects; default cleanup after 30 days, with options to skip persistence or purge project records. Whether an agent can delete a particular deployment’s files depends on its permissions.","Eligible Claude Enterprise local sessions: Anthropic captures API-visible exchanges server-side; Compliance API retrieval endpoints are read-only. Default retention is six years, subject to organization retention settings and documented eligibility exclusions. This is not a record of all device activity.","Anthropic’s Compliance Activity Feed starts when enabled, is not backfilled and records administrative and resource activity rather than session content. Configured Claude Code OpenTelemetry delivery is another, customer-collector path; prompt and tool-detail capture require separate settings.","OpenAI Agents SDK: tracing is on by default for eligible organizations and its client-side batch processor exports to OpenAI. Application code can disable tracing or add or replace processors for customer export; tracing is unavailable under ZDR. Do not extend this SDK documentation to every product called an Agents API.","Grok Bot Enterprise: administrative audit logs are not action traces. Action Recording is separately enabled, stores sanitized action categories in an internal store for 90 days, and requires additional configuration for OpenTelemetry export to a customer collector. Recorded actions do not appear on the Audit Log page.","Classify a boundary as documented only where the supplied source describes its mechanism; otherwise mark tamper resistance not established. Treat the paper’s tested harnesses as context, not as a test of these provider-held or customer-held records."],"metrics":[{"label":"Verified observations","value":"3","detail":"3 measured fields"},{"label":"Supported claims","value":"9","detail":"9 material findings"},{"label":"Cited sources","value":"8","detail":"8 primary or authoritative"},{"label":"Research score","value":"82","detail":"Automated topic and evidence score"}],"columns":[{"key":"entity","label":"Entity"},{"key":"metric","label":"Metric"},{"key":"value","label":"Value"},{"key":"unit","label":"Unit"},{"key":"observed","label":"Observed"},{"key":"source","label":"Source"},{"key":"transform","label":"Transform"}],"data":[{"unit":"years","value":"6 years; subject to a finite organization conversation-retention setting","entity":"Claude Enterprise Compliance API","metric":"Captured local-session transcript default retention","source":"https://platform.claude.com/docs/en/manage-claude/compliance-sessions","observed":"2026-09-27","transform":null},{"unit":"days","value":"90 days","entity":"Grok Bot Enterprise","metric":"Internal Action Recording retention when enabled","source":"https://docs.x.ai/grok-bot/security","observed":"2026-09-27","transform":null},{"unit":"days","value":"30 days","entity":"Claude Code","metric":"Local transcript default cleanup age","source":"https://code.claude.com/docs/en/claude-directory","observed":"2026-09-27","transform":null}],"sources":[{"url":"https://platform.claude.com/docs/en/manage-claude/compliance-integration-patterns","name":"Anthropic","title":"Design your compliance integration","records":0},{"url":"https://code.claude.com/docs/en/claude-directory","name":"Anthropic","title":"Explore the .claude directory - Claude Code Docs","records":1},{"url":"https://docs.x.ai/grok-bot/teams-and-enterprises","name":"SpaceXAI Docs","title":"Grok Bot for teams and enterprises | SpaceXAI Docs","records":0},{"url":"https://docs.x.ai/grok-bot/security","name":"SpaceXAI Docs","title":"Grok Bot security | SpaceXAI Docs","records":1},{"url":"https://arxiv.org/abs/2609.30266","name":"arXiv","title":"LLM Agents Can Easily Tamper With Their Own Traces","records":0},{"url":"https://code.claude.com/docs/en/monitoring-usage","name":"Anthropic","title":"Monitoring - Claude Code Docs","records":0},{"url":"https://openai.github.io/openai-agents-python/tracing","name":"OpenAI","title":"openai.github.io","records":0},{"url":"https://platform.claude.com/docs/en/manage-claude/compliance-sessions","name":"Anthropic","title":"Retrieve session transcripts","records":1}],"provenance":{"publisher":"Superpower Daily","source_count":8,"source_urls":["https://platform.claude.com/docs/en/manage-claude/compliance-integration-patterns","https://code.claude.com/docs/en/claude-directory","https://docs.x.ai/grok-bot/teams-and-enterprises","https://docs.x.ai/grok-bot/security","https://arxiv.org/abs/2609.30266","https://code.claude.com/docs/en/monitoring-usage","https://openai.github.io/openai-agents-python/tracing","https://platform.claude.com/docs/en/manage-claude/compliance-sessions"],"methodology":["Evidence matrix plan: use separate rows for Claude Code local transcripts, eligible Claude Enterprise Compliance API transcripts, the Compliance Activity Feed, Claude Code OpenTelemetry export, OpenAI Agents SDK tracing, Grok Bot Enterprise audit logs, Grok Bot Action Recording and its optional customer export. Columns: recorded content, capture location, default state, eligibility, destination, retention or deletion, coverage gaps and documented tamper-resistance mechanism.","Claude Code local transcripts: plaintext conversation and tool records under ~/.claude/projects; default cleanup after 30 days, with options to skip persistence or purge project records. Whether an agent can delete a particular deployment’s files depends on its permissions.","Eligible Claude Enterprise local sessions: Anthropic captures API-visible exchanges server-side; Compliance API retrieval endpoints are read-only. Default retention is six years, subject to organization retention settings and documented eligibility exclusions. This is not a record of all device activity.","Anthropic’s Compliance Activity Feed starts when enabled, is not backfilled and records administrative and resource activity rather than session content. Configured Claude Code OpenTelemetry delivery is another, customer-collector path; prompt and tool-detail capture require separate settings.","OpenAI Agents SDK: tracing is on by default for eligible organizations and its client-side batch processor exports to OpenAI. Application code can disable tracing or add or replace processors for customer export; tracing is unavailable under ZDR. Do not extend this SDK documentation to every product called an Agents API.","Grok Bot Enterprise: administrative audit logs are not action traces. Action Recording is separately enabled, stores sanitized action categories in an internal store for 90 days, and requires additional configuration for OpenTelemetry export to a customer collector. Recorded actions do not appear on the Audit Log page.","Classify a boundary as documented only where the supplied source describes its mechanism; otherwise mark tamper resistance not established. Treat the paper’s tested harnesses as context, not as a test of these provider-held or customer-held records."],"snapshot_hash":"3e8827f7ed7e4d1c7cbe73789fbf8a5ad364dedace3c5c85802a709f2aed9c53"},"distributions":{"csv":"https://superpowerdaily.com/api/research/agent-audit-trails-which-records-are-outside-the-agent-s-reach-f30f7187/versions/v1?format=csv","json":"https://superpowerdaily.com/api/research/agent-audit-trails-which-records-are-outside-the-agent-s-reach-f30f7187/versions/v1?format=json"}}