Research investigation R0927 / comparison
Agent Audit Trails: Which Records Are Outside the Agent’s Reach?
A visible transcript is not necessarily an independently preserved audit record. Capture location, recording defaults, coverage, deletion paths and export timing determine what an operator may be able to reconstruct.
Snapshot only. There is not enough history to claim a trend yet.
Version ledger
Frozen public editions
Each edition preserves the records, method, sources, and downloads available at publication time.
Evidence and documentation descriptions are frozen at the supplied collection cutoff, September 27, 2026, 15:30:50 UTC. This is a synthesis of saved sources, not a new documentation collection, configuration review or tampering experiment.
- Dataset ID
- spd:agent-audit-trails-which-records-are-outside-the-agent-s-reach-f30f7187
- Stable URL
- /research/agent-audit-trails-which-records-are-outside-the-agent-s-reach-f30f7187
- Version
- v1
- Coverage
- 2026-09-27
- Records
- 3
- Fields
- 7
- Updated
Measurement technique
How to read this report
- 01Evidence matrix plan: use separate rows for Claude Code local transcripts, eligible Claude Enterprise Compliance API transcripts, the Compliance Activity Feed, Claude Code OpenTelemetry export, OpenAI Agents SDK tracing, Grok Bot Enterprise audit logs, Grok Bot Action Recording and its optional customer export. Columns: recorded content, capture location, default state, eligibility, destination, retention or deletion, coverage gaps and documented tamper-resistance mechanism.
- 02Claude Code local transcripts: plaintext conversation and tool records under ~/.claude/projects; default cleanup after 30 days, with options to skip persistence or purge project records. Whether an agent can delete a particular deployment’s files depends on its permissions.
- 03Eligible Claude Enterprise local sessions: Anthropic captures API-visible exchanges server-side; Compliance API retrieval endpoints are read-only. Default retention is six years, subject to organization retention settings and documented eligibility exclusions. This is not a record of all device activity.
- 04Anthropic’s Compliance Activity Feed starts when enabled, is not backfilled and records administrative and resource activity rather than session content. Configured Claude Code OpenTelemetry delivery is another, customer-collector path; prompt and tool-detail capture require separate settings.
- 05OpenAI Agents SDK: tracing is on by default for eligible organizations and its client-side batch processor exports to OpenAI. Application code can disable tracing or add or replace processors for customer export; tracing is unavailable under ZDR. Do not extend this SDK documentation to every product called an Agents API.
- 06Grok Bot Enterprise: administrative audit logs are not action traces. Action Recording is separately enabled, stores sanitized action categories in an internal store for 90 days, and requires additional configuration for OpenTelemetry export to a customer collector. Recorded actions do not appear on the Audit Log page.
- 07Classify a boundary as documented only where the supplied source describes its mechanism; otherwise mark tamper resistance not established. Treat the paper’s tested harnesses as context, not as a test of these provider-held or customer-held records.
Sources
Evidence
5 publishers supporting 3 records. Expand a publisher to inspect its cited pages.