Skip to main content
Each row of the Audit Log is one tool call: the moment an agent added a note, updated a ticket, reset a password, ran a script, or read something from your PSA, RMM, or Microsoft 365. Open it from Reporting → Audit Log in the dashboard. Use it when you want to know “did one of my agents do this?” — a ticket that changed status, a note nobody remembers writing, a user that was disabled. Search the ticket number or the user’s name and the log shows which agent acted, when, with what input, and what came back.
The log covers triggered agents, scheduled agents, and chat agents at once, and is scoped to your tenant. What you see follows your workflow access: an admin sees every agent; a user or viewer sees the agents they created or that were shared with them. It keeps 30 days of history.

What each row shows

Click a row to expand it. The expanded view shows the exact input the agent sent to the tool, a summary of what the tool returned (the first 400 characters), the tool’s internal name, and an Open run link to the full execution trace — every thought, tool call, message, and complete tool result of that run.

Finding an action

  • Search matches the ticket number, user, device, or any other value in the tool’s input, as well as the tool and agent names. Type a ticket number to see everything any agent did on that ticket.
  • All tools narrows the log to one tool, with the number of calls in the last 30 days next to each.
  • All agents narrows it to one agent.
  • Errors shows only calls that failed.
Rows load 50 at a time, newest first. Use Load older actions at the bottom to page back through the 30-day window.
Tool inputs are recorded with credentials and secrets masked. Loading a Neo skill shows as “Skill loaded” rather than the skill’s content.