Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

One audit trail for every coding agent, and what it proves

Blog post from WorkOS

Post Details
Company
Date Published
Author
Jônatas Santos
Word Count
1,671
Company Posts That Month
58
Language
English
Hacker News Points
-
Post removed?
No
Summary

WorkOS’s open-source audit harness adds centralized audit logging to coding agents including pi, Claude Code, Codex, and OpenClaw by capturing session, prompt, tool, and turn lifecycle events through shared plugins and sending them to a WorkOS organization. The system supports queries through an AuthKit-protected console, Audit Logs Export API, SIEM streaming, and MCP tools, while storing hashes and previews rather than complete prompts or tool content to limit sensitive data retention. To avoid placing powerful API keys on developer laptops, events are sent through an mTLS-protected Cloudflare Worker that validates device certificates, maps managed devices to users through an MDM, stamps trusted identity data, and uses a server-side secret for ingestion. The project addresses operational choices such as unknown devices, MDM outages, supported device-management systems, configuration rollout, and macOS-only certificate-based emission, but it emphasizes that laptop-generated events cannot conclusively prove an action occurred or that reporting was complete because users can fabricate or suppress events. Comparing audit activity with vendor billing data can identify sessions with no logs, while stronger integrity would require coding-agent vendors to generate server-side audit records or signed receipts for each model turn.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
OpenClaw 4 33 13 8 -89%
MCP 2 3,789 413 151 -65%
Real-time 1 2,081 529 162 -65%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.