Audit Logs & Telemetry

Ephos provides comprehensive visibility into agent activity through immutable audit logs, ensuring that every non-human interaction with your credentials is accounted for.

Why Runtime Telemetry Matters: Autonomous systems operate across dynamic tools, external services, and delegated identities. Ephos provides attribution and execution visibility for every proxied request without exposing persistent credentials to the agent runtime.

Execution Telemetry

For every request routed through the Ephos Gateway, we record:

  • Timestamp: Precise ISO-8601 execution time.
  • Identity: The specific Ephos Token ID used.
  • Destination: The target hostname and path.
  • Status: HTTP response code from the target API.
  • Attribution: Agent labels and metadata provided in the request.

Execution Snapshots (Pro Tier)

Subscribers on the Pro plan gain access to Execution Snapshots, which securely store request and response payloads for 30 days to support debugging, incident response, and execution tracing.

Zero-Access Header Scrubbing: Prior to archiving a forensic snapshot, the Ephos Enclave strictly redacts all sensitive authorization headers—including X-Ephos-Derived-Key, X-Ephos-Token, Authorization, Cookie, and internal service secrets. Plaintext credentials are never persisted in forensic archives.

Execution Timeline

The Audit tab in your dashboard provides a real-time feed of these events. You can filter logs by token, domain, or date range to investigate suspicious activity or monitor usage patterns.

Multi-Tenant Governance & RBAC

Audit log visibility and lifecycle management are governed by strict Role-Based Access Control (RBAC) boundaries:

  • Organization Administrators: Possess full governance authority. Admins can view the complete organization audit log across all members and tokens, and export full CSV audit histories.
  • Organization Members: Possess a strictly scoped view. Members can only view audit logs generated by their own personal activity within the organization and are restricted from exporting CSV audit histories.

Subscription Tier Retention & Quotas

Audit log retention schedules and advanced telemetry features are enforced based on your organization's active subscription tier:

Free Plan

Essential execution visibility for solo developers and early-stage agent workflows.

  • 7-Day Execution Telemetry Retention
  • • Standard Runtime Telemetry Feed
  • • 25k Monthly Gateway Requests

Plus Plan ($15)

Production-grade governance and telemetry for growing autonomous systems.

  • 15-Day Execution Telemetry Retention
  • • Advanced Search & Filtering
  • • 75k Monthly Gateway Requests
  • • Delegated Execution Authentication

Pro Plan ($30)

Forensic-grade telemetry and long-term execution attribution for production infrastructure

  • 30-Day Execution Telemetry Retention
  • Execution Snapshots
  • • Full CSV/JSON Export
  • • Advanced Runtime Attribution