To investigate an unwanted change made by an AI agent, build a timestamped evidence chain from the person or service that started the work, through the agent session and tool call, to the operation recorded by the system that owns the affected resource. A trace can show what the agent attempted; the target system’s audit record is the evidence to use when confirming whether the change was applied.
What to establish in an AI agent investigation
Answer three questions separately: Which identity performed the change? Did the tool call succeed? Which target-side log confirms the result? Agent runtimes, identity services, approval systems, and cloud or SaaS platforms record different parts of the event. No single log is guaranteed to show the full chain.
Preserve the identifiers each system provides, including trace, span, session, thread, call, actor, and resource IDs. A matching identifier can make a join strong; when systems have no shared ID, document the basis for correlating their records rather than presenting an inferred match as certain.
Investigation workflow
1. Set the incident window and preserve original records
Record when the change was first noticed, the affected resource, the suspected agent, and the relevant environment. Preserve original trace and audit exports before routine processing or retention limits remove useful context. For each collection, note the source system, query or filter, time range, export time, and timezone so another responder can reproduce it. Export and retention capabilities vary by platform; preservation is an incident-handling step, not a guarantee that any particular vendor retains records for a fixed period.
Recommended Free Tools
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
2. Separate the identities in the actor chain
Do not treat “the agent” as a complete attribution. Where the platform exposes them, distinguish the initiating human or service, application, agent blueprint, agent instance, and service principal or other identity used against the target. Microsoft Entra Agent ID records can identify agent activity through identity types and fields such as agentType, initiatedBy, performedBy, targetResources, and blueprintId. Agent sign-in activity may appear in different sign-in log types depending on whether access used delegated or app-only permissions. See Microsoft Entra Agent ID sign-in and audit logs.
Capture the exact actor and target values as logged. An agent instance may be linked to a blueprint, but that link does not by itself identify the human who initiated a particular run or prove which identity changed the resource.
3. Reconstruct the agent execution path
Open the relevant session and inspect its turns and spans. In the OpenAI Agents API tracing model, generation spans can record inputs and outputs; tool spans can include the tool name, arguments, result when available, status, and error details. Session traces can be exported as OTLP JSON when tracing export is enabled and the API key has the required trace or agent read permission. Traces may become available after a turn finishes, and the recorded content depends on platform behavior and organizational data controls. Consult OpenAI’s Agents API tracing guide.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
For the documented Azure SRE Agent environment, inspect its customEvents for model generation, tool execution, session lifecycle, routing, and handoff activity. Tool telemetry can include the tool name, input, output, calling subagent, and call ID. Shared fields such as TraceId, SpanId, ParentSpanId, ThreadId, and CorrelationId help follow a request through that agent’s activity. The field set is specific to the documented environment; see Azure SRE Agent audit guidance.
Read the tool result and status carefully. A request recorded in a trace may have failed, returned an error, or shown only an attempted operation. A successful-looking tool result still does not substitute for checking the target system’s own record and current resource state.
4. Confirm the operation in the system that owns the resource
Search the affected cloud, SaaS, code, or data service for the operation on the specific resource. Check the target-side timestamp, actor, operation, resource identifier, and outcome, then inspect the current state if appropriate. For Azure Resource Manager changes involving Azure SRE Agent resources, Microsoft distinguishes agent action telemetry from the Azure Activity Log, which records resource-management operations such as create, update, or delete. For AWS environments, guidance recommends monitoring agent tool use with CloudTrail and CloudWatch, setting metrics and alarms for deviations, and aggregating logs centrally to correlate patterns across sessions and users. These are platform-specific recommendations, not evidence that every agent runtime automatically emits the same fields. See AWS Prescriptive Guidance for generative AI agents.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
5. Compare the action with authorization and policy
Compare the requested task with the actual tool, its arguments and result, the user or agent identity, the effective permissions, any approval decision, and the target-side operation. Determine whether the tool was available to that agent, whether human approval was expected, and whether the permissions granted were broader than the task required.
AWS recommends least-privilege permissions for agent roles and warns that broad permissions can enable privilege escalation through combinations of tools. OpenAI’s Codex safety article describes activity exports that can include approval decisions, tool results, MCP use, and network proxy allow-or-deny events. That event set applies to the described Codex activity logging and should not be assumed for every agent product. See Running Codex safely at OpenAI.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →6. Treat prompt and response content as a separate evidence question
Do not assume an audit event contains prompt or response text. Microsoft’s AI investigation playbook describes Unified Audit Log records as metadata-first: they can establish who did what, when, and with which resources, without necessarily capturing prompt or response content. When content review is needed, the playbook directs investigators to Microsoft Purview eDiscovery or DSPM for AI; access may require additional permissions and legal coordination. OpenAI traces can include recorded generation inputs and outputs in some circumstances, but visibility depends on the platform and its configuration. See the Microsoft AI Investigation Playbook.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
For Microsoft Copilot and AI application audit events, Purview supports filtering by operation. Provider or model details may be present for some requests and absent when automatic or internal model selection is used; retention policies can be configured. See Microsoft Purview audit logs for Copilot and AI applications.
7. Assemble a defensible timeline
Place identity and sign-in events, agent traces, approval decisions, network events, and target-system operations in chronological order. Keep original timestamps and source identifiers alongside any normalized timeline. Note timezone, clock, ingestion-delay, and retention limitations when known. Mark each cross-system join as confirmed or inferred; if there is no shared identifier, state the correlation basis, such as actor, resource, and a narrow time window.
Some trace data may only be available after a turn completes, and an export may include only traces available at export time. In Microsoft’s documented Entra environment, provider or model details can also be absent for some automatic routing cases. These are reasons to record what each source can and cannot establish, not to fill gaps with assumptions.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
8. Contain and recover through the affected system’s process
Once the action and likely scope are understood, follow the organization’s incident procedure to constrain the relevant identity or tool path, assess impact, and restore the resource through its approved change process. The appropriate containment and recovery steps depend on the target service and the type of change; retain both the action history and evidence of restoration in the incident record.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What each logging source can establish
Choose evidence sources to cover the full chain rather than expecting one product to serve as a universal agent audit log.
| Evidence source | Useful for | Important boundary |
|---|---|---|
| OpenAI Agents API tracing | Recorded generation and tool spans, session activity, and OTLP JSON trace export. | Export must be enabled and the API key needs appropriate read permission; content availability depends on what is recorded and organizational controls. OpenAI tracing guide. |
| Microsoft Entra Agent ID logs | Agent-related identity activity, actor and target fields, blueprint linkage, and sign-in records. | Sign-ins may appear in different log types depending on permissions and flow. Entra Agent ID logs. |
| Azure SRE Agent telemetry and Azure Activity Log | Documented agent custom events and correlation fields, plus Azure Resource Manager operations. | Agent telemetry and Azure resource operations are separate evidence sources; the described fields apply to Azure SRE Agent. Azure SRE Agent audit guidance. |
| AWS CloudTrail, CloudWatch, and agent observability guidance | Monitoring tool use, alerting on deviations, and central log aggregation in AWS environments. | The guidance does not establish that every agent runtime emits identical events or fields. AWS agent security guidance. |
| Microsoft Purview audit and content workflows | Operation-filtered audit events, configurable retention, and a path to content-level review when needed. | Audit metadata may not include prompt or response text; some model metadata may be omitted. Purview audit guidance and the AI Investigation Playbook. |
| Codex activity logging described by OpenAI | OpenTelemetry activity that can include prompts, tool approvals and results, MCP use, and network proxy decisions. | This is a product-specific event description, not a universal agent logging format. OpenAI Codex safety article. |
Keep the investigation record usable
A practical evidence record should let another responder understand what happened without confusing an agent’s narrative with system evidence. Preserve:
- The affected resource and the target system’s operation and outcome.
- The exact actor, identity, session, trace, span, tool-call, and resource identifiers available in each source.
- Original timestamps, timezones, collection times, queries, filters, and export files.
- Approval, policy, permission, and relevant network events.
- Which cross-system links are confirmed and which are inferred, with the reason for each inference.
- Known gaps, such as unavailable content, missing model details, delayed traces, or records outside retention.
- Containment and restoration actions, along with evidence of the resulting resource state.
Use the organization’s existing logging and security monitoring stack where it can retain and correlate these records. Least privilege and anomaly monitoring can reduce exposure and improve detection, but logging by itself does not prevent an agent from taking an unwanted action.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

