# Auditing

Every tool call — on either surface — writes exactly one row to the append-only `mcp_events`
log: the tool, the outcome (`ok`, `error` or `denied`, so a guardrail refusal is recorded
distinctly), the surface (`mcp` or `rest`), the duration, and the call arguments with
secret-shaped keys redacted. The log is visible in the console and cannot be updated or deleted,
including by the platform.

:::tip

Every REST response carries an `X-Request-Id` — quote it in support requests and it maps to one
audit row.

:::
