Answer

An audit trail of everything the AI did? What SAGARIS records, and what it does not

SAGARIS keeps an audit trail of what its AI agent and writing agents do. Every action the agent plans, proposes, is refused or completes is recorded with its inputs, evidence and outcome, and when a person approves or rejects one, the record names who. Its eight writing agents keep the prompt they sent and the text they got back. It is not everything: some model calls, such as call transcription, sit outside it.

Checked against the SAGARIS product code on 25 September 2026.

What SAGARIS records about what its AI did

There is not one log, there are several, and each answers a different question. These are the ones that concern the AI.

What the AI agent did

Each tool call the agent makes is written to the workspace's activity trail at whatever stage it reaches: planned, held for approval, proposed, completed, failed, refused, stopped by the outbound switch or skipped as a duplicate. The row keeps the parameters with sensitive values redacted, the policy verdict, the evidence and citations the agent relied on, and what it reported back. Each run is recorded too, with the plan it made.

Who approved or rejected it

When an owner, admin or sales lead decides on an agent action, the decision stores who decided, when, any reason they gave and a receipt of what actually happened, and a matching row lands in the activity trail under that person's name. Approving a proposal to email a contact still sends nothing, and the receipt says so.

What the writing agents were given and wrote

Eight agents do the writing: person research, company research, a person digest, a company digest, the narrative plan, the message writer, the out-of-office follow-up writer and the social post writer. Each model call they make is traced with the prompt as sent and the raw response, each kept up to 60,000 characters, the parsed output, tokens, cost and latency, and the contact, sequence and step it was for.

Model calls made through the gateway

Model calls made through the SAGARIS model gateway get a usage row before the call starts, naming the provider, the purpose, tokens, latency and whether it succeeded. If that row cannot be written, the call does not happen.

Changes to how the AI is allowed to behave

The configuration trail keeps before and after values for settings such as the workspace autonomy level, plus API keys created and revoked. Prior values are redacted unless the prior value is itself part of the record. Switching inbox Auto-Mode on or off is not among the recorded changes.

Data exports

Each attempt on the data export routes is recorded, allowed or refused, with the export type, the permission checked, the record count and the format. An export whose record cannot be written is refused rather than released.

Who can read it

Reading is split by role, and the split is not the same for every record.

Any member of the workspace

Can read the activity trail in summary: the action, who took it, the model and the time. Can read the model usage ledger. Can also read the writing agents' traces with the prompt and response included, which is wider access than the activity trail gives, so decide who is in the workspace with that in mind.

Admins only

The full input and output recorded on an activity row, when read through the audit trail and its endpoint, because it can contain the content of the thing being audited. Asking that endpoint for it without an admin role is refused outright rather than answered with the payload quietly removed. The configuration trail is admin-only as well, and a non-admin is told so rather than shown an empty list. Some outcomes, such as the result of a consent or suppression check, also appear on the compliance screen, which members can open.

From inside the product, not the public API

The trail is read in the product by a signed-in member. None of the public API's operations reads audit records, an API key cannot pull them, and there is no export or download of the trail today.

What the trail does not do

If a specific action has to be provably recorded for your own compliance programme, check it against this list before assuming the presence of an audit trail covers it.

It is not tamper-evident

The rows carry no stored hash links. There is a verification endpoint, and it answers that no persisted chain is available rather than returning a result. We would rather say that than let the words audit trail imply it.

There is no retention control

The product has no configurable audit retention period and nothing trims the trail on a schedule. Call recordings have a retention setting of their own; it does not apply to the audit trail.

Not every model call is in the usage ledger

A few model calls do not go through the gateway today, among them call transcription, generated speech and the classifier that decides how a dialed call was answered. Calls made by the AI voice agent and the AI receptionist are kept as call records and transcripts rather than as activity-trail rows.

Records are mostly written after the action

For most of these trails, a write that fails does not stop or undo what the AI did. Data exports are the deliberate exception: an export whose record cannot be written is refused. Downloading a saved report as a file is not in the export trail.

Deleting an account changes the trail

When a person's account is deleted, their activity rows in workspaces they did not own stay but no longer name them, decisions they made stop naming them, and agent actions they requested are removed. Deleting an owner's account deletes their workspace, and its trail with it.

Some AI writing and one setting are outside it

The prompt behind an inbox reply draft is not kept: the reply's text and its usage row are, but it is not one of the writing-agent traces. Switching inbox Auto-Mode on or off is not written to the configuration trail, so the trail will not show who armed it or when.

Questions buyers ask next

  • MOST ASKED

    Yes, for its AI agent and its writing agents. Each agent tool call is recorded at every stage it reaches with its parameters, the policy verdict and the evidence it used, a decision on an agent action names the person who made it, and the writing agents keep the prompt they sent and the text they got back. It does not cover every model call, and this page names the ones it misses.

  • Yes. A decision on an agent action stores who decided, when, any reason they gave and a receipt of what actually happened, and writes a matching row to the activity trail under that person's name. A reply draft that a rep sends records which rep sent it.

  • For the writing agents, yes. Each model call they make is traced with the prompt as sent and the raw response, each kept up to 60,000 characters, along with tokens, cost and the contact, sequence and step it was for. Any member of the workspace can read these traces.

  • Any member can read the activity trail in summary, the model usage ledger and the writing-agent traces. The recorded input and output on an activity row, and the configuration trail, are for admins only. It is read inside the product; the public API does not expose it and there is no export of the trail today.

  • No. The rows carry no stored hash links, and the verification endpoint says so rather than returning a result. If your programme needs tamper evidence, the trail does not provide it today.

  • There is no configurable retention period and nothing trims the trail on a schedule, so no period is promised either way. Call recordings have their own retention setting, and it does not apply to the audit trail.

Book a demo