Skip to main content

Audit vs telemetry

Fact0 has two parallel pipelines:
For high-value events (LLM spend, customer data access, refunds) log to both.

Comparison Matrix

Correlation Best Practice

When executing complex multi-agent steps, always include the telemetry execution_id inside the audit event’s metadata dictionary. This connects an audit record to its execution DAG. Verification checks the stored record and its chain; it does not establish that the source action happened exactly as reported.

Audit log

  • Endpoints: /v1/events, /v1/events/batch
  • Storage: audit_events - SHA-256 hash chain per tenant
  • Auth: f0_live_* API keys (read/write scopes)
  • Use for: recorded history, integrity checks and signed exports

Execution telemetry

  • Endpoints: /api/v1/executions/*
  • Storage: executions, spans, execution_events
  • Auth: f0_live_* API keys (same local instance keys as the audit log)
  • Use for: DAG visualization, replay, debugging non-deterministic agents

Span kinds (telemetry)

Audit event shape

The core commits ingestion synchronously. SDK-side batching is separate from server-side asynchronous ingest. A policy-evaluation span records a decision made by your own agent; it does not enable Fact0 enforcement. See Event schema and Executions.