Audit records tool-call metadata so administrators can verify who used which
app, through which AI client, and with what outcome. Stackyapper does not retain
tool inputs or provider response bodies in the Audit table.
Verify a first call
Open Audit after completing a bounded read.
Confirm the workspace and approximate time.
Confirm the actor and AI client.
Confirm the app and tool.
Confirm the outcome and duration.
Investigate a denied call
Check:
Whether the app is available and connected.
The user's effective group and direct policy.
Explicit tool restrictions.
Whether confirmation was required but not completed.
Whether the call was made in the intended workspace.
Do not broaden an entire app grant until you identify the exact missing tool.
Investigate an error
Open the app first if its state is Needs attention. Otherwise compare the
Audit timestamp with the provider's own service health and authorization logs.
Retry only with a harmless read until the connection is healthy.
Export
Use Export CSV after applying the narrowest useful filters. Treat exports as
operational records: store them in an approved location and apply your
company's retention policy.