An LLM observability log can show the prompt, the tool name, and the latency. Useful for debugging. Not enough for an auditor.
When someone asks "what did this agent do, and why was it allowed?", you need an authorization envelope at the enforcement boundary:
Logging only after the tool runs misses the control point. Prefer the PDP or MCP gateway that decides before execution.
I work at Permit.io — we wrote up the minimum evidence package for an AI agent audit trail: