Read the Agent audit log
How do I read the Agent audit log and find one action?
Agent → Audit logs in the sidebar holds every action your agent has taken. Four tiles summarise the period you have selected; the table below lists the most recent actions inside it. Narrow it with the search box or the Initiator, Status and Date controls, open any row for its step-by-step detail, and use Export to download exactly what is on screen.
Start by reading the tiles for what they measure
All four follow the Date control, and each answers a different question.
Actions in period counts everything the agent did in the window — chat turns, playbook runs and scheduled jobs together. Credits in period is the credit ledger's own total for that window, not the sum of the rows on screen, which is why it can be far larger than the table. Failure rate prints its own arithmetic underneath, so you can tell 0.5% of a few actions from 0.5% of thousands.
Capabilities used is the one to read carefully, because the sub-label is the accurate part: it counts distinct skills the agent invoked, not how many capabilities you have connected. Zero usually means the period was plain conversation with no named skill pinned to it, and never means your integrations are missing. What is connected lives on Capabilities in the sidebar, which is a different thing entirely.
Narrowing it down
The search box matches an action's name, its target and who started it. Initiator lists only the people and automations that actually appear in the log, so it never offers a name that would return nothing. Status filters to Success, Failed, Awaiting or Running, and Failed only is the shortcut for the one people want most.
Date — This month, Last 24 hours, Last 7 days, Last 30 days, Last 90 days — does more than filter. It sets the window the tiles measure and how far back rows are fetched, which is why the line beneath reads 87 actions in view · most recent only, widen the range to load more. When something you expected is not in the table, widening the range is the fix rather than scrolling.
You may not see a Client or Capability dropdown here at all. Both appear only when the log carries those values, and today it usually does not, so this page cannot be scoped to one client.
What one action is, and what is inside it
An action is one thing the agent did end to end: a single chat turn, one playbook run, one scheduled job. Select the chevron on a row to open it up, or tick Show internal steps (LLM + MCP) to expand every row at once.
Those indented lines are the work inside that one action — the model calls it made and any tool it reached for. Each carries its own status, credits and duration, and together they add up to the row's figure, which is what makes this the place a slow or expensive action explains itself. Some step labels are the engine's internal names rather than plain English; read the status, credits and duration and ignore the naming.
Open → goes further. A playbook row opens that run's own page; everything else opens a panel with the run summary — who started it, status, duration, credits, model — and the same list of steps. Some turns have no step record, and the panel says so rather than showing an empty table.
Export the audit log
Export downloads the rows you are looking at, in the order you are looking at them, as a CSV. Your filters apply, so a Failed only view of last week exports as exactly that. The file carries the table's columns plus each action's model and capability, and the internal steps come too when Show internal steps is on. The button is greyed out on an empty table, so a click always means something.
Export is manual and per view. There is no scheduled or emailed version of this report, and no setting anywhere that turns one on — if you need it weekly, you download it weekly.
How this relates to your credit usage
Both pages read the same ledger, so for the same window they agree: set Date to This month and the Credits in period tile here is the Credits used headline on Agent → Home. They divide the work, though. Home tells you which service spent your credits; this page tells you which action did. Chasing an unexpectedly large month usually means starting on Home to find the service, then coming here with the range set to match.


