All documentation

Documentation Everywhere else

Audit events: approvals and refusals

The second page of the audit catalogue: questions asked before acting, refusals, and outside material treated as data.

The second of the audit catalogue's three pages: every question a seat asked before acting, every refusal, and the moments the room treated outside material as data. The first page has the runs and what a delivery looks like; the third has seats, the record of the work and the team.

Approvals and refusals

TypeReported byWhenDetail carries
approval.answeredMac and serverA person answers a question a seat asked before acting.id, decision, remembered, from
approval.withdrawnMacA seat stopped waiting before anyone answered.id, kind
policy.boundMacA run started under a profile bound to its project or to automations.profile, automation
policy.refusedMacA tool rule or a sequence policy refused a call.tool, reason, command
sandbox.refusedMacThe kernel sandbox refused a command's reach outside the workspace.command, paths
egress.refusedMacA connection to a host not on the allowlist was refused.command, hosts
allow.removedMacA remembered allow rule was withdrawn.rule, dir
ask_person.askedMacA seat put questions to the person.count
ask_person.answeredMacThe person answered them, or skipped.answered
instructions.allowedMacThe person allowed a folder's instruction files for a run.files, dir
instructions.ignoredMacThe person declined a folder's instruction files for a run.files, dir
instructions.skippedMacNobody was there to allow a folder's instruction files, so they were not read.files, why
outside.instructionsMacMaterial from outside the discussion carried instructions, which were treated as data.source
secrets.maskedMacCredentials in a run's turns or tool results were masked before leaving the Mac.count, kinds
mcp.changedMacAn MCP server's tools differ from what was approved; they are withheld until approved again.server, added, removed, changed
mcp.approvedMacThe person allowed a changed MCP server's new definitions.server
mcp.refusedMacThe person declined a changed MCP server; it stays connected and silent.server
mcp.registryMacThe team's MCP registry file changed since it was last fetched.url, added, removed
judge.sentenceMacThe Smart-mode judge asked because one of the team's or the member's sentences applied.sentence, tool
production.touchedMacA call touched one of the team's production markers and was asked about or refused.marker, tool, action
memory.rejectedMacA memory the room had extracted was forgotten before anyone accepted it.scope
retention.sweptMac and serverThe team's retention period deleted closed discussions past it.count, days
warden.stoppedMacThe warden seat stopped a run because an action was not part of the job, or followed an injected instruction.tool, why
guardrail.violationMac and serverWhat a person asked tripped one of the team's guardrails; logged, warned about or refused by its level.kind, level, why
secret.usedMacA run's commands were given the team's or the member's secrets, by name.names
settings.changedMacA guardrail-relevant setting changed on this Mac: policies, rules, hooks, MCP servers, remembered allows, folder trust, the mode.keys

Who reports them

Reported by Mac means the member's app observed it and reported it; a Mac with admin access could suppress it. Server means our servers observed it themselves. Every refusal on this page carries the reason in words, never the content that was refused: a command's text, yes; a file's contents or a page's words, never.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.