LESSON · 28 SEPTEMBER 2026
How to build an AI agent activity record your SOC can use
The verdict
Record every allowed, asked and denied agent action with the user, device, agent, tool, arguments, outcome and whether a person prompted it, then send it to your SIEM. The hard part is attribution: separating what a person did from what an agent did on their behalf, which only some tools on this site describe.
By Best AI Security editors · 28 September 2026 · 3 min read
Why does agent activity need its own record?
Endpoint logs show a process running a command. When a coding agent runs that command, the process is the agent, and the person who started it may not have asked for that step. Without an agent-level record, an investigation cannot tell a developer's command from one the agent chose after reading a malicious file. The MCP tools specification asks clients to log tool usage for audit purposes.
What should each record hold?
- Time, device and the signed-in user.
- The agent and its version, and the MCP server and tool if one was called.
- The action and its arguments, with secrets redacted.
- The decision: allowed, asked (with the user's answer) or denied, and the rule that made it.
- Whether a person prompted this step or the agent chose it, and the chain from the prompt to the system action.
- What the agent read just before, when it came from outside content such as a web page or an MCP result.
How do tools on this site describe audit?
| Tool | What its public pages say about records and audit |
|---|---|
| Bay | Records who triggered each action, whether a human was involved, and the chain from prompt to system action. |
| Lasso Security | Keeps a history of inputs, policy decisions and enforcement actions for audit-ready reports. |
| Onyx Security | Integrates with Okta, Entra, Splunk and CrowdStrike. |
| Harmonic Security | Can log silently as well as block or warn. |
Koi, Prompt Security and Bloom Security do not describe agent versus human attribution on the pages we reviewed, which is why they score lower on that criterion in our rankings.
What changed in MCP for audit?
The 2026-07-28 MCP specification removed protocol sessions, so there is no connection-level identity to rely on. Clients should identify themselves on each request, and the changelog documents OpenTelemetry trace context (traceparent, tracestate, baggage) carried in request metadata, which gives a standard way to link an MCP call to a wider trace. Our note on the specification has the detail.
How do you make the record useful to the SOC?
- Send records to the SIEM you already use, with the same user and device identifiers as your EDR and identity logs.
- Start with a small set of detections: a denied action followed by a retry, an agent reading credential files, a new MCP server on an approved agent.
- Review asked actions weekly. If users approve an ask almost every time, the rule may belong in allow.
- Keep retention in line with your other security logs, and agree who may read records that include prompts.
What should you ask vendors?
- Show the record for one agent session, from prompt to system action.
- How do you mark an action as agent-initiated rather than human-initiated?
- Which SIEM integrations exist today, and which fields are exported?
Next lesson
Related
Sources
- MCP tools specification · Reviewed Sep 2026
- MCP changelog, 2026-07-28 · Reviewed Sep 2026
- Bay · Reviewed Sep 2026
- Lasso Security, AI usage control · Reviewed Sep 2026
- Onyx Security, AI security · Reviewed Sep 2026
- Harmonic Security · Reviewed Sep 2026