Audit data and retention
Audit records, device inventories, and product analytics have different purposes and access rules.
| Data | Guidance |
|---|---|
| MCP/LLM request metadata and payloads | MCP audit logs and LLM audit logs |
| One-time and scheduled exports | Audit Log Exports |
| Device scans and captured files | Inventory and local auditing |
| Aggregate telemetry and consent | Product Analytics |
| Encrypted fields | Encryption coverage |
MCP audit logs, LLM audit logs, and device scans have separate retention settings in Server Configuration. Their documented defaults are 90 days; setting the corresponding retention value to zero disables its automatic cleanup. Export records before expiration when longer retention is required.
Admin and Owner can view audit metadata; sensitive gateway request/response payloads require the Auditor add-on role. Export permissions follow the same distinction. Device scan access and captured-file behavior are documented separately—do not assume every collected field has identical restrictions.
Captured configuration files can contain sensitive content even when structured scan fields omit secret values. Field encryption does not protect exported objects or all metadata; configure destination storage permissions and encryption separately.
Product-analytics consent is separate from update checks. See the analytics guide for what is collected and the relevant configuration controls.
The MCP Platform provides visibility into MCP and LLM gateway activity through audit logs and usage tracking. These features help with monitoring, compliance, and understanding how MCP servers and LLM gateway models are being used.
Sensitive data (MCP request/response bodies) can only be viewed by users with the Auditor role. All other roles, including Owner and Admin, see only metadata for these resources. The Auditor role is an add-on permission that can be combined with any other role, granting read-only access to sensitive data across the platform. See User Roles for details.
MCP Audit Logs
Audit logs capture all MCP interactions that flow through the gateway.
What's Logged
- MCP Requests: Tool calls, resource access, and other MCP operations
- MCP Responses: Results returned from MCP servers
- User Information: Who made the request
- Timestamps: When the request occurred
- Server Information: Which MCP server handled the request
Viewing Audit Logs
Navigate to Operations > Audit Logs, then select MCP in the MCP Platform.
The audit log view shows:
- Timestamp
- User
- MCP Server
- Operation type
- Status (success/failure)
Detailed View
Click on any log entry to see additional details:
- Request and response metadata
- Error details (if applicable)
- Full request/response payloads and headers (Auditor role required)
Filtering
Filter logs by:
- Date range
- User
- MCP Server
- Operation type
- Status
Retention
Audit logs are automatically deleted after 90 days by default. To preserve logs beyond this period, use the export functionality before they are deleted. See Server Configuration for retention settings.
Exporting Audit Logs
MCP audit logs can be exported for external analysis, compliance requirements, or long-term retention. See Audit Log Export for configuration options.
Usage
Usage tracking provides aggregate statistics about MCP server activity.
Metrics Available
- Request counts: Total requests per server
- User activity: Which users are using which servers
- Tool usage: Most frequently called tools
- Error rates: Success/failure ratios
- Response times: Performance metrics
Viewing Usage
Navigate to Operations > Usage in the MCP Platform.
Use Cases
- Cost management: Understand which servers are most used
- Capacity planning: Identify servers that may need scaling
- Adoption tracking: See which tools are popular
- Troubleshooting: Identify servers with high error rates
Access by Role
Power User / Power User+
- View audit logs and usage for their own activity
- Metadata only (no request/response content)
Admin / Owner
- View audit logs and usage for all users
- Export MCP and LLM audit logs
- Metadata only (no request/response content)
Auditor (add-on)
- View full request/response payloads and headers
- Export audit logs with full content
- Read-only access to admin views
Privacy Considerations
Audit logs may contain sensitive information from MCP requests/responses and LLM gateway requests/responses. Consider:
- Data retention: Configure how long logs are kept (see Retention)
- Access control: Limit who can view detailed logs
- Export security: Secure any exported log data
- Compliance: Ensure logging meets regulatory requirements
Creating Exports
Configure export storage and credentials first. MCP and LLM exports share the storage configuration.
One-Time Exports
One-time exports allow you to export MCP or LLM audit logs for a specific time range with optional filters.
-
Navigate to Audit Logs:
- For MCP audit logs, go to Operations → Audit Logs → MCP
- For LLM audit logs, go to Operations → Audit Logs → Model
- Apply any desired filters
-
Create Export:
- Click "Create Export" → "Create One-time Export"
- If filters are applied, you'll be asked whether to include them
-
Configure Export:
- Name: Descriptive name for the export
- Bucket: Storage bucket name where exports will be saved
- Key Prefix: Path prefix within the bucket. If empty, defaults to
mcp-audit-logs/YYYY/MM/DD/for MCP exports andllm-audit-logs/YYYY/MM/DD/for LLM exports, based on the current date. - Time Range: Start and end dates/times
- Filters: Additional filters to apply
-
Submit Export:
- Click "Create Export" to start the process
- Monitor progress in the exports list
Scheduled Exports
Scheduled exports run automatically at specified intervals.
-
Create Schedule:
- Click "Create Export" → "Create Export Schedule"
- Configure the same options as one-time exports
-
Schedule Configuration:
- Frequency: Hourly, Daily, Weekly, or Monthly
- Time: Specific time to run (for daily/weekly/monthly)
- Day: Day of week (weekly) or month (monthly)
- Bucket: Storage bucket name where exports will be saved
- Key Prefix: Path prefix within the bucket. If empty, defaults to
mcp-audit-logs/YYYY/MM/DD/for MCP exports andllm-audit-logs/YYYY/MM/DD/for LLM exports, based on the current date.
-
Manage Schedules:
- View and manage schedules in the "Export Schedules" tab
- Enable/disable schedules as needed
- Edit schedule configuration