Audit Logging
Tollgate maintains a complete audit log of all tool calls, policy decisions, and user approvals. This enables compliance reporting, debugging, and security analysis.What’s Logged
Every tool call records:| Field | Description |
|---|---|
timestamp | When the call occurred |
server | MCP server name |
tool | Tool being called |
arguments | Tool arguments (optionally redacted) |
policyDecision | What the policy said (allow, deny, prompt) |
userDecision | What the user chose (for prompts) |
result | Whether the call succeeded |
durationMs | How long the call took |
riskLevel | Analyzer-determined risk |
Viewing Logs
Recent Activity
Statistics
Exporting Logs
Export for compliance reporting or SIEM integration:Filtering Exports
PII Redaction
By default, tool arguments are redacted in logs to protect sensitive data:Disabling Redaction
For debugging, you can export with original data:[!CAUTION] Non-redacted exports may contain PII, credentials, or sensitive data. Handle with appropriate security controls.
Storage Location
Audit logs are stored in SQLite at:--audit-path:
Retention
Tollgate does not automatically delete old logs. For compliance, implement your own retention policy:SIEM Integration
Splunk
Datadog
CloudWatch
Compliance
Tollgate audit logs support:- SOC 2: Complete access logging with user attribution
- GDPR: PII redaction by default
- CCPA: Data access visibility
- HIPAA: Audit trail for PHI access (when properly configured)