Skip to main content
Glama

audit_log

Read-onlyIdempotent

Query a tamper-evident log of every secret read, write, or delete to trace who accessed a key and when. Filter by key, agent, or action to build an access timeline.

Instructions

[audit] Query the q-ring audit log — a tamper-evident record of every read/write/delete touching a secret. Use to investigate 'who accessed KEY recently?' or to feed an agent the access timeline for a specific credential; prefer detect_anomalies for automated unusual-pattern detection and health_check for decay-state-plus-anomalies in one call. Read-only. Returns one line per event in chronological order, formatted timestamp | action | key | [scope] | env:NAME | detail. Returns 'No audit events found' when the filter matches nothing.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
keyNoLimit to events touching this exact key. Omit for the full log.
agentNoLimit to events stamped with this agent label (clientInfo name@version). Omit for all agents.
limitNoMaximum events to return, newest first. Defaults to 20. Increase for deeper investigations.
actionNoLimit to a single action verb (e.g. 'read' to see only reads). Omit for all actions.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changedv0.17.5
    • changedInput schema / properties / action / enum
      Previous value: -[
      -  "read",
      -  "write",
      -  "delete",
      -  "list",
      -  "export",
      -  "generate",
      -  "entangle",
      -  "tunnel",
      -  "teleport",
      -  "collapse",
      -  "canary",
      -  "wrap"
      -]New value: +[
      +  "read",
      +  "write",
      +  "delete",
      +  "list",
      +  "export",
      +  "generate",
      +  "entangle",
      +  "tunnel",
      +  "teleport",
      +  "collapse",
      +  "approve",
      +  "revoke",
      +  "policy_deny",
      +  "rotate",
      +  "push",
      +  "wrap"
      +]
    • addedInput schema / properties / agent
      Added value: +{
      +  "description": "Limit to events stamped with this agent label (clientInfo name@version). Omit for all agents.",
      +  "type": "string"
      +}
  2. Changed1 schema field changedv0.16.1
    • changedInput schema / properties / action / enum
      Previous value: -[
      -  "read",
      -  "write",
      -  "delete",
      -  "list",
      -  "export",
      -  "generate",
      -  "entangle",
      -  "tunnel",
      -  "teleport",
      -  "collapse"
      -]New value: +[
      +  "read",
      +  "write",
      +  "delete",
      +  "list",
      +  "export",
      +  "generate",
      +  "entangle",
      +  "tunnel",
      +  "teleport",
      +  "collapse",
      +  "canary",
      +  "wrap"
      +]
  3. Changed3 schema fields changedv0.11.7
    • changedInput schema / properties / action / description
      Previous value: -"Filter by action"New value: +"Limit to a single action verb (e.g. 'read' to see only reads). Omit for all actions."
    • changedInput schema / properties / key / description
      Previous value: -"Filter by key"New value: +"Limit to events touching this exact key. Omit for the full log."
    • changedInput schema / properties / limit / description
      Previous value: -"Max events to return"New value: +"Maximum events to return, newest first. Defaults to 20. Increase for deeper investigations."
  4. First observedv0.1.0

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, and destructiveHint=false, so the safety profile is covered by structured data. The description nevertheless adds the tamper-evident nature, chronological one-line-per-event format, and the exact empty-result string. It doesn't mention pagination behavior, which is a minor remaining gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two dense sentences with no wasted words; the core definition leads, then usage routing, then behavioral details. Slightly packed but well front-loaded and every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Complete for a read-only filtered-list tool with no output schema: it defines scope, routes to two alternatives, declares read-only, specifies the return line format and the empty-result message. An agent has everything needed to call and interpret it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and each parameter already documents omit-for-all semantics, so the schema does the heavy lifting. The description adds only the example 'read' for the action filter, which is marginal value. Baseline 3 is appropriate when the schema is fully documented.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Query) and resource (the q-ring audit log), and immediately characterizes it as 'a tamper-evident record of every read/write/delete touching a secret'. The bracket prefix '[audit]' and the framing make it unmistakably distinct from siblings like export_audit, verify_audit_chain, or detect_anomalies.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives concrete when-to-use examples ('who accessed KEY recently?', feeding an access timeline) and explicitly routes to alternatives: 'prefer detect_anomalies for automated unusual-pattern detection and health_check for decay-state-plus-anomalies'. Names two siblings and the condition selecting each.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.