Audit Trail
Every CLI invocation and MCP tool call is logged.
What's logged
- Timestamp
- Tool or endpoint called
- Data categories accessed
- Agent identity (truncated API key prefix)
- Request and response metadata (no full payloads)
Full payloads are not stored — only the metadata sufficient to answer "who accessed what, when?"
Where to view
- Console — UI inspector
- JSON export — full audit log download
Retention
Audit entries are retained for the lifetime of your account. Export them at any time for external compliance archiving.
What it's good for
- Spotting unauthorized access (alerts you to revoke a key)
- Compliance and HIPAA documentation
- Debugging an agent that's making the wrong calls
- Internal review before granting wider scopes
Privacy
Audit data is yours alone. Betterness staff cannot access your audit log without your explicit consent (e.g. when you open a support ticket).

