AI Agent Governance: What Microsoft Agent 365 Changes
Microsoft Agent 365 adds a registry, agent identities, and audit controls for AI agents. Learn what it covers, what it costs, and the small-business version.
Every AI agent action should leave a trace. Learn what to log, how long to keep it, and a lightweight audit trail setup that fits a small business.
An AI agent that books jobs, sends messages, and updates your CRM is doing real work in your name. Work leaves paperwork, or at least it should. An audit trail is simply the paperwork for agent work: a timestamped record of what the agent did, what it was told, what data it touched, and who approved the sensitive parts. Without it, the first dispute, a wrong refund, a message a customer denies receiving, a booking nobody ordered, becomes your word against nobody's.
Most owners set up logging after an incident. The incident is usually small: a customer says your system confirmed an appointment that was never on the calendar, or two people disagree about what the agent promised on a call. With a log, you replay the conversation and the actions in minutes. Without one, you reconstruct from memory, and memory loses.
There is a second reason. Agents act while you sleep, which is the point of hiring them, but it means actions accumulate without anyone watching. A weekly glance at what your agents did is the management layer that replaces standing over someone's shoulder. Microsoft treats this as enterprise infrastructure: Agent 365, generally available since May 1, 2026, includes audit and eDiscovery support through Purview plus OpenTelemetry-based observability as core controls. The enterprise version streams into monitoring dashboards. Your version can be a checklist and a spreadsheet, as long as the underlying records exist.
If you have not set up the surrounding governance yet, read AI agent governance and Microsoft Agent 365 first for the big picture, then come back here for the logging specifics.
Every meaningful agent action should capture these seven fields. Meaningful means anything a customer sees, anything touching money or schedules, and anything reading or writing customer data. Purely internal read-only lookups can be summarized rather than recorded line by line.
| Field | What to capture | Why it matters later |
|---|---|---|
| Timestamp | Date, time, and time zone of the action | Establishes sequence when events pile up |
| Agent identity | Which agent acted, under its own login | Separates one agent's work from another's |
| Trigger | The request, message, or schedule that started it | Shows why the agent acted at all |
| Action | What the agent actually did | The core fact under dispute |
| Data touched | Records read, written, sent, or deleted | Scopes privacy and compliance exposure |
| Outcome | Success, failure, or partial completion | Distinguishes attempts from effects |
| Approval | Who approved it, when, under what rule | Proves a human was in the loop |
For customer-facing agents, keep the conversation record alongside these fields. The transcript is often the fastest way to resolve a disagreement, and it shows exactly what the customer was told. Vendors that provide conversation histories and action logs out of the box save you from building any of this yourself; it is a fair question to ask before you buy, and our internal assistant service ships with both.
A common mistake is logging only completed actions. The decisions around the action matter just as much: what was requested, who approved or rejected it, when, and under which policy. Rejected requests are worth keeping because they show your controls working, and overrides, where someone approved outside the normal tier, deserve a note explaining why.
This is standard practice on the major platforms, not exotic process. ChatGPT Dots, announced September 29, 2026, can hold actions for approval with an Activity View where the owner watches and redirects. Claude Cowork runs on per-task approvals, with an admin-controlled automatic mode for trusted routines. Your logging should mirror the same decision points: requested, approved or denied, by whom, executed or blocked. When something goes wrong later, that decision chain is what turns a confusing mess into a diagnosable event.
One practical rule: never let the agent approve its own exceptions. If an action falls outside its normal authority, the approval must come from a human, and the log should show that clearly. Self-approved exceptions are how small overreaches become large ones.
Retention is where owners either keep everything forever, which becomes unsearchable, or delete aggressively and regret it. A tiered approach works better:
Store logs where they cannot be silently edited by the same agent that produced them. Read-only exports to separate storage, or a vendor dashboard with tamper-evident history, both satisfy this. The point is simple: a log the actor can rewrite is not a log.
Here is the whole system, sized for a company without an IT department:
That is the entire program. It will not impress an enterprise auditor, but it answers every question a customer, a vendor, or a small-claims filing is likely to ask: what happened, when, why, and who said yes.
What is an AI agent audit trail?
It is a timestamped record of what an agent did, what instructions it received, what data it touched, and which human approved the sensitive steps. Microsoft Agent 365, generally available since May 1, 2026, treats audit and eDiscovery support through Purview as a core governance control, and OpenTelemetry-based observability lets agent activity flow into standard monitoring tools. Even without enterprise software, a simple chronological log covers most needs.
What should a small business log for each agent action?
Log the timestamp, the agent's identity, the triggering request, the action taken, the data or systems touched, the outcome, and any human approval with who gave it and when. For customer-facing agents, also keep the conversation record. That set answers the three questions that matter later: what happened, why did it happen, and who approved it.
How long should agent logs be kept?
Keep routine operational logs at least 90 days so you can investigate billing disputes and customer complaints. Keep logs tied to money movement, contracts, or regulated data for one to seven years depending on your industry and state rules, matching whatever retention you already apply to the underlying records. When unsure, ask your accountant or attorney before deleting anything.
How do approvals fit into an audit trail?
Log the decision, not just the action. Record what was requested, who approved or rejected it, when, and under what policy tier. Platforms show this is standard practice: ChatGPT Dots can require approval for actions with an Activity View for oversight, and Claude Cowork uses per-task approvals with an admin-controlled automatic mode. Your log should capture the same decision points.
This week, check whether each of your agents produces an exportable log of its actions and approvals, and confirm every agent runs under its own login. If either answer is no, fix that before adding new automations. Our free six-step AI automation plan reviews your current setup end to end: start your AI automation plan. To walk through it with someone, book a call.
Microsoft Agent 365 adds a registry, agent identities, and audit controls for AI agents. Learn what it covers, what it costs, and the small-business version.
AI agents will make mistakes. Learn the four error types, a calm 48-hour containment plan, and the approval and logging habits that prevent repeats.
AI agents touch customer data, so compliance matters. Learn the 2026 basics on privacy, disclosure, sector rules, and vendor contracts owners need.
More articles: browse the full Praktivo blog.