### Documentation
Get started
- [Surfaice documentation](/docs/ai)
- [What is Surfaice?](/docs/concepts/what-is-surfaice/ai)
- [Quickstart](/docs/quickstart/ai)
- [Start by role](/docs/guides/start-by-role/ai)
- [Sign in and SSO](/docs/guides/sign-in/ai)
Guides
- [Workspaces](/docs/guides/workspaces/ai)
- [Connectors](/docs/guides/connectors/ai)
- [Chat with Hugo](/docs/guides/chat-with-hugo/ai)
- [Skills](/docs/guides/skills/ai)
- [Working with Hugo](/docs/guides/working-with-hugo/ai)
- [Punch Walk Guide](/docs/guides/punch-walk/ai)
- [Lease abstraction](/docs/guides/lease-abstraction/ai)
Use cases
- [Use cases overview](/docs/use-cases/overview/ai)
- [Teams & personas](/docs/use-cases/by-team/ai)
- [Lease administration](/docs/use-cases/lease-administration/ai)
- [CAM reconciliation](/docs/use-cases/cam-reconciliation/ai)
- [Store development](/docs/use-cases/store-development/ai)
- [Construction & closeout](/docs/use-cases/construction-and-closeout/ai)
- [Portfolio & renewals](/docs/use-cases/portfolio-and-renewals/ai)
- [Operations & facilities](/docs/use-cases/operations/ai)
Skills library
- [Skills library](/docs/skills/ai)
- [Lease & portfolio skills](/docs/skills/lease-and-portfolio/ai)
- [Store development skills](/docs/skills/store-development/ai)
- [Estimating & bid skills](/docs/skills/estimating-and-bids/ai)
- [Reporting & briefing skills](/docs/skills/reporting/ai)
- [Apps & automations](/docs/skills/apps-and-automations/ai)
- [Workspace admin skills](/docs/skills/workspace-admin/ai)
Concepts & trust
- [Permissions](/docs/concepts/permissions/ai)
- [Data handling](/docs/concepts/data-handling/ai)
- [Agent limitations](/docs/concepts/hugo-limitations/ai)
- [Trust FAQ](/docs/concepts/trust-faq/ai)
- [Audit trail](/docs/concepts/audit-trail/ai)
Help
- [Release notes](/docs/release-notes/ai)
- [Security overview](/docs/security/ai)
- [Status](https://status.surfaice.pro)
- [Open app](https://agent.surfaice.pro)
Get started
- [Surfaice documentation](/docs/ai)
- [What is Surfaice?](/docs/concepts/what-is-surfaice/ai)
- [Quickstart](/docs/quickstart/ai)
- [Start by role](/docs/guides/start-by-role/ai)
- [Sign in and SSO](/docs/guides/sign-in/ai)
Guides
- [Workspaces](/docs/guides/workspaces/ai)
- [Connectors](/docs/guides/connectors/ai)
- [Chat with Hugo](/docs/guides/chat-with-hugo/ai)
- [Skills](/docs/guides/skills/ai)
- [Working with Hugo](/docs/guides/working-with-hugo/ai)
- [Punch Walk Guide](/docs/guides/punch-walk/ai)
- [Lease abstraction](/docs/guides/lease-abstraction/ai)
Use cases
- [Use cases overview](/docs/use-cases/overview/ai)
- [Teams & personas](/docs/use-cases/by-team/ai)
- [Lease administration](/docs/use-cases/lease-administration/ai)
- [CAM reconciliation](/docs/use-cases/cam-reconciliation/ai)
- [Store development](/docs/use-cases/store-development/ai)
- [Construction & closeout](/docs/use-cases/construction-and-closeout/ai)
- [Portfolio & renewals](/docs/use-cases/portfolio-and-renewals/ai)
- [Operations & facilities](/docs/use-cases/operations/ai)
Skills library
- [Skills library](/docs/skills/ai)
- [Lease & portfolio skills](/docs/skills/lease-and-portfolio/ai)
- [Store development skills](/docs/skills/store-development/ai)
- [Estimating & bid skills](/docs/skills/estimating-and-bids/ai)
- [Reporting & briefing skills](/docs/skills/reporting/ai)
- [Apps & automations](/docs/skills/apps-and-automations/ai)
- [Workspace admin skills](/docs/skills/workspace-admin/ai)
Concepts & trust
- [Permissions](/docs/concepts/permissions/ai)
- [Data handling](/docs/concepts/data-handling/ai)
- [Agent limitations](/docs/concepts/hugo-limitations/ai)
- [Trust FAQ](/docs/concepts/trust-faq/ai)
- [Audit trail](/docs/concepts/audit-trail/ai)
Help
- [Release notes](/docs/release-notes/ai)
- [Security overview](/docs/security/ai)
- [Status](https://status.surfaice.pro)
- [Open app](https://agent.surfaice.pro)
# Audit trail
What Surfaice logs about agent runs, who can see it, and how to use it in reviews.
Enterprise teams need to answer: **who asked the agent to do what, using which systems, and what was produced?**
**Hugo** is Surfaice’s in-app AI agent, “agent runs” and “Hugo runs” mean the same thing. Surfaice maintains an audit trail of that activity for workspace administrators and compliance reviewers.
## What is logged
| Event | Typical fields recorded |
| --- | --- |
| User message / skill invocation | User identity, workspace, timestamp, channel |
| Tool and connector use | Which integration was called (for example Lucernex read, SharePoint file, mailbox search) |
| Agent output | Artifacts generated, citations, saved workspace objects |
| Errors | Failed tool calls (for support diagnosis) |
Exact retention period and export format depend on your customer agreement. Request details in the NDA security package via [security@surfaice.pro](mailto:security@surfaice.pro).
## What is not a substitute for audit logs
- **PostHog / product analytics**, funnel and usage metadata, not full message bodies
- **Chat UI scrollback**, convenient for users, not the compliance system of record
- **Source systems**, Lucernex and SharePoint retain their own access logs
## Who can access audit data
- **Workspace administrators**, operational review and support
- **Your IT / security team**, via agreement-defined export or questionnaire process
- **Surfaice support**, only when engaged for an incident, under contract
End users should not expect to browse every other user's prompts unless your admin has granted that capability.
## Using audit trails in practice
**During rollout:** sample 10-20 agent runs per week. Confirm connectors match approved scope and no unexpected mailbox reads occur.
**For Vanta / SOC 2:** point reviewers to [Security overview](/docs/security/ai), [Trust FAQ](/docs/concepts/trust-faq/ai), and the NDA Application Architecture Diagram for logging boundaries.
## Related
- [Trust FAQ](/docs/concepts/trust-faq/ai)
- [Data handling](/docs/concepts/data-handling/ai)
- [Permissions](/docs/concepts/permissions/ai)