Audit Microsoft Copilot, Salesforce Agentforce, and custom AI agents with the same evidence questions, then collect each platform’s native records and fill the documented gaps. The shared method covers the accountable owner, identities, authority, configuration, policy, tool effects, human decisions, outcomes, incidents, retention, export, and integrity. Platform logs supply part of that record. The enterprise assembles the cross-system evidence needed to support its audit conclusion.
This guide covers Microsoft 365 Copilot and agents built with Microsoft Copilot Studio under the Microsoft section. Product editions, licenses, tenant settings, channels, and enabled services change the records available to a specific enterprise. The Salesforce section covers Agentforce Session Tracing and related Salesforce controls. Source review completed 28 July 2026.
Use one common audit object across all three platforms
Apply these ten items to every sampled agent action. Each platform section maps its collection steps back to this same object. Keep the enterprise population, control owner, audit period, test procedure, source record, and failure condition explicit.
This operating object extends the 12-domain enterprise AI agent audit framework. The enterprise framework covers audit planning, population completeness, sampling, findings, and follow-up. This page focuses on platform collection and normalization.
- 1. Inventory and accountable owner: identify the agent, business purpose, environment, lifecycle state, and person accountable for outcomes.
- 2. User, agent, service, and delegated identities: resolve every principal involved in the request and execution.
- 3. Permissions, connected tools, and data boundaries: reconstruct effective authority at the time of action.
- 4. Model, instructions, configuration, and Release: preserve the executable versions and approved change record.
- 5. Policy decisions and approval gates: record the evaluated inputs, rule version, outcome, reasons, reviewer authority, and expiry.
- 6. Tool calls and downstream effects: bind arguments, destination, result, and before and after state.
- 7. Human intervention, override, and escalation: preserve who intervened, under which authority, using which evidence.
- 8. Execution lineage and business outcome: order the action events and reconcile the intended outcome with the observed result.
- 9. Incident, revocation, and rollback: connect containment, access removal, compensation, recovery, and restart decisions.
- 10. Retention, export, integrity, and independent verification: document record coverage, retention class, export method, chain of custody, and verification result.
Platform comparison table
Read each vendor cell as a collection lead for the tenant and licenses under review. Validate the named setting and record in the sampled environment before reaching a completeness conclusion.
| Evidence question | Microsoft Copilot | Salesforce Agentforce | Custom AI agents |
|---|---|---|---|
| Native administrative and audit records | Microsoft Purview Audit records Copilot user interactions and administrative activities when tenant auditing is enabled. Copilot Studio audit fields cover agent and component identifiers and update details. | Agentforce Session Tracing records sessions, turns, reasoning-engine executions, actions, prompt and gateway inputs and outputs, errors, and responses in Data 360. Setup Audit Trail covers tracked setup changes. | Application logs, identity-provider records, configuration history, policy decisions, approval records, tool receipts, downstream state, incidents, and evidence manifests chosen by the enterprise. |
| Identity and permission model | Copilot Studio authentication supports Microsoft Entra ID and configured OAuth 2.0 providers. Power Platform data policies can require authentication and restrict knowledge sources, tools, HTTP endpoints, channels, and event triggers. | Agentforce action access guidance distinguishes logged-in user context from an assigned agent user and identifies permission requirements for Flow, Apex, Knowledge, and Data 360. The auditor must resolve the active channel and execution context. | Workforce identity, workload identity, delegated principal, credential, role, entitlement, purpose, environment, resource, and time window must be explicit in the event and supporting IAM evidence. |
| Approval or intervention controls | Copilot Studio data policies can block publication or use of selected connectors, knowledge sources, HTTP endpoints, channels, and triggers. The cited Purview audit pages do not define one universal pre-execution human approval record for every Copilot action. | Agentforce Operations can assign an AI agent and a human to the same task so the agent waits for human review before submission. That control belongs to the separately licensed Operations workflow and does not establish universal coverage for every Agentforce action. | The enterprise defines allow, warn, require_approval, and block rules, binds the proposed action, checks reviewer authority, records the decision, and revalidates before execution. |
| Tool and data-access evidence | Purview Copilot audit records can include references to files, sites, emails, and other accessed resources. Copilot Studio Audit identifies plugin operations and transcript thread IDs. | Agentforce Session Tracing models session steps and references to LLM calls. The OTel export includes action executions in a unified session response. | Instrument each tool boundary with the effective identity, permission decision, arguments digest, destination, result digest, and downstream receipt. |
| Export, retention, and integration path | Purview Audit export supports portal CSV and Search-UnifiedAuditLog export. Purview retention policies depend on licensing and configured policy. Copilot Studio eDiscovery guidance describes search and export of retained interactions. | Data 360 session-trace objects support queries and reports. The beta OTel API supports single-session pull into an OTLP collector. | Send structured events to an append-only evidence store, apply the approved retention class, export a manifest with artifact digests, and verify the package independently. |
| Known scope limits in current primary documentation | Copilot Studio Audit stores the transcript separately and places only its thread ID in the Audit record. Channels can be excluded from logging, and tenant administrators can disable Purview event logging. | Session Tracing setup says tracing starts disabled. The beta OTel API supports one session per request and returns sessions started within the previous 72 hours. | Coverage equals the implemented instrumentation. Uninstrumented side effects, alternate workers, direct database writes, and missing identity context remain audit gaps. |
| Evidence a cross-platform layer must capture | Preserve the accountable owner, delegated identity, exact configuration and Release, enterprise policy rationale, approval authority, cross-system correlation, verified downstream state, incident links, and independently checkable integrity. | Preserve the accountable owner, exact deployed metadata, enterprise policy rationale, approval authority outside covered workflows, cross-system correlation, verified downstream state, retention decision, and independently checkable integrity. | Preserve the complete ten-part audit object and explicit source provenance for each field. |
Microsoft Copilot: collect Purview, configuration, and effect records
Microsoft Purview Audit records the user, time, location, application context, and references to resources accessed for a Copilot interaction when auditing is enabled. Purview also records administrative activity for Copilot settings, plugins, promptbooks, and workspaces. These records establish who interacted with a Copilot surface and which Microsoft 365 resources the event references.
Copilot Studio Audit adds agent IDs, component IDs, update details, plugin operation identifiers, and the transcript thread ID. Its Audit event omits the full interaction text. Microsoft documents transcript access through DSPM for AI, which attempts to retrieve chat text and accessed-resource links. Record whether DSPM content capture, transcript storage, the relevant channel, and permissions were active for the audit period.
Copilot Studio authentication can use Microsoft Entra ID or a configured OAuth 2.0 provider. Power Platform data policies can require authentication and restrict knowledge sources, connector tools, HTTP endpoints, skills, channels, and event triggers. Export the effective authentication setting, agent sharing, connector credential mode, data policies, endpoint filters, environment roles, and referenced Entra identity records.
Purview export guidance supports CSV and Search-UnifiedAuditLog workflows. Copilot Studio compliance guidance describes eDiscovery collection for retained interactions. Resolve actual tenant licensing, enabled audit services, policy configuration, export limits, and retention before stating coverage.
- Native evidence: Purview interaction events, Copilot Studio admin and usage fields, accessed-resource references, plugin operation identifiers, and transcript references.
- Identity evidence: Entra or configured OAuth identity, maker and administrator identities, service or connector credential mode, agent sharing, environment roles, and delegation.
- Intervention evidence: data-policy enforcement and any Process-specific human review record. Preserve the held action and reviewer decision separately when the business process requires approval.
- External evidence: enterprise policy inputs and reasons, exact model and instruction Release, downstream tool receipt, before and after state, cross-system lineage, rollback, and independent integrity verification.
- Coverage statement: name the Copilot product, agent, channel, tenant, environment, audit services, licenses, policy settings, and time range examined.
Salesforce Agentforce: collect session traces, authority, and Salesforce effects
Agentforce Session Tracing stores detailed interaction data in Data 360. Salesforce describes turn-by-turn interactions, reasoning-engine executions, actions, prompt and gateway inputs and outputs, errors, and final responses under a session ID. Its data model exposes DLOs and DMOs for queries and reports and references LLM calls for joins with audit, feedback, or guardrail data.
Salesforce action-access guidance distinguishes channels that run in a logged-in user context from channels that use an assigned agent user. It also names Flow, Apex, Knowledge, Data 360, object, and feature permissions that may govern an action. Export the agent assignment, user and agent permission sets, profiles, sharing rules, object and field access, action definitions, connected Flow or Apex access, and customer identity mapping that applied to the sampled session.
Agentforce Operations human review can hold an AI-assigned task for a human assignee to review and complete. Treat that as evidence for the covered Operations task. Preserve any approval implemented through a Flow, custom action, external system, or business procedure from its own source.
The Agentforce Session Trace OTel API is a beta, OAuth-protected single-session export. Its current documentation limits retrieval to sessions started within the previous 72 hours. Build collection around Data 360 queries and the enterprise retention decision, and use the beta API only within its documented window and terms.
- Native evidence: session, interaction, message, step, LLM, action, error, metric, and feedback data where Session Tracing and related collection are enabled.
- Configuration evidence: agent metadata and version fields, subagents or topics, instructions, actions, model selection, deployment record, Setup Audit Trail, and change package or source-control evidence.
- Authority evidence: logged-in user or assigned agent user context, permission assignments, sharing and field access, action-specific permissions, customer verification, and effective session context.
- External evidence: enterprise policy evaluation, approval evidence outside the traced workflow, downstream state in Salesforce and connected systems, incident and rollback links, retention rationale, and independent integrity verification.
- Coverage statement: name the org, agent type, channel, execution context, Data 360 data space, enabled tracing controls, licenses, API path, and audit period examined.
Custom AI agents: make the evidence contract part of execution
A self-built agent gives the enterprise direct control over instrumentation and direct responsibility for completeness. Create the audit event at the policy and tool boundaries. The event should use stable identifiers across the request, policy decision, approval, tool call, downstream receipt, incident, and rollback.
Resolve identity before the agent reads restricted data or requests a side effect. Evaluate effective authority against the exact resource, purpose, environment, destination, and time. Bind the configuration digest, model version, instruction version, policy digest, arguments digest, and presented evidence digest to the record.
Write tool receipts after the downstream system confirms the effect. Reconcile the business outcome separately from transport success. Store privacy handling, retention class, evidence artifacts, record hashes, signatures, and verification results with the event. Treat absent instrumentation as a scoped audit limitation.
- At request: capture the requester, delegated user, service identity, agent, owner, resource, purpose, Data Boundary, and correlation IDs.
- At policy: capture the policy and input digests, outcome, matched rules, reasons, and evaluation time.
- At approval: capture the bound request, required role, reviewer, evidence digest, expiry, decision, and rationale reference.
- At tool execution: capture tool identity and version, destination, arguments digest, idempotency key, result, and downstream effects.
- At closure: capture the business outcome, rollback state, ordered lineage, evidence manifest, privacy treatment, and integrity verification.
Common minimum-evidence checklist
Apply this checklist without changing the questions. Record a pass, fail, unavailable, or out-of-scope verdict for every row and explain every unavailable source.
| Common audit item | Minimum evidence | Completion test |
|---|---|---|
| Inventory and accountable owner | Agent ID, purpose, environment, lifecycle state, dependency map, and named accountable person. | The sampled action resolves to one approved inventory record and one accountable owner. |
| User, agent, service, and delegated identities | Stable identity references, identity provider, execution context, delegation, and credential source. | Every actor in the request and effect is attributable at the action time. |
| Permissions, tools, and data boundaries | Effective grants, roles, sharing, tool list, resource scope, purpose, environment, and expiry. | The auditor can reproduce why the action had or lacked authority. |
| Model, instructions, configuration, and Release | Version identifiers, content digests, approval, deployment time, and change record. | The executable configuration for the action can be identified and compared with the approved Release. |
| Policy decisions and approval gates | Policy version, inputs, outcome, reasons, request binding, reviewer authority, decision, and expiry. | The policy and human decision precede every governed side effect. |
| Tool calls and downstream effects | Tool, action, destination, arguments digest, result, receipt, and state evidence. | The downstream system confirms the recorded effect under the same correlation. |
| Human intervention, override, and escalation | Actor, authority, evidence viewed, action taken, reason, time, and resulting state. | Every intervention is authorized, attributable, and tied to the affected execution. |
| Execution lineage and business outcome | Ordered events, execution status, outcome status, summary, and source reference. | Sequence and outcome reconcile across platform and downstream records. |
| Incident, revocation, and rollback | Incident reference, containment, access revocation, rollback or compensation, restart decision, and owners. | The enterprise can show the safe state and the authority for recovery. |
| Retention, export, integrity, and verification | Retention class, enabled settings, export log, chain of custody, artifact digests, hash, signature, and verification result. | An independent reviewer can retrieve the scoped package and verify every supported integrity claim. |
Platform-specific collection checklist
Collect configuration evidence before the audit period closes, then sample action records and reconcile them with downstream systems. Product names and admin paths can change; use the linked source and confirm the current tenant interface.
| Platform | Collection location or API | Collect and reconcile |
|---|---|---|
| Microsoft Copilot | Microsoft Purview portal Audit search and export; DSPM for AI and eDiscovery; Power Platform data policies; Copilot Studio Activity; agent Security, Authentication, and Analytics. | Export CopilotInteraction and relevant admin events, accessed-resource references, agent and plugin IDs, transcript references and retained content, authentication and data policies, agent sharing, component versions, and connected-tool configuration. Reconcile with Entra and every downstream system changed by the action. |
| Salesforce Agentforce | Setup > Einstein Audit, Analytics, and Monitoring Setup; Data 360 session tracing DLOs and DMOs; beta OTel API; Setup Audit Trail; Agentforce DX metadata reference. | Export session, participant, message, step, action, LLM, error, and feedback records; agent metadata and active version; agent or user execution context; permission assignments; human-review or Flow evidence; Salesforce record history; external action receipts; retention and data-space configuration. |
| Custom AI agents | Agent runtime, identity provider, policy engine, approval service, tool gateway, deployment system, downstream systems, incident system, and evidence store. | Export one correlated event chain for the full ten-part object. Recompute digests, confirm downstream state, verify ordering, test revocation or rollback, and run the independent verifier on the sealed package. |
Instrument a custom-agent event against the public schema
The synthetic IT access event below records a temporary privileged-group membership. The policy returns require_approval, a directory administrator approves before expiry, the directory tool returns a receipt, and the event records the resulting business outcome.
The example follows the public AI Agent Audit Log Schema. Its integrity block carries synthetic hash and signature-shaped values and sets verification to not_performed. This makes the absence of verification explicit and avoids a verifier claim. The repository test compiles the public JSON Schema with Ajv 2020 and validates this exported constant.
{
"schema_version": "1.0.0",
"audit_event": {
"event_id": "evt_01K1CM8R9K2Q7M1W3D5N6P8X0A",
"event_type": "agent.action.completed",
"occurred_at": "2026-07-28T08:42:18.481Z",
"recorded_at": "2026-07-28T08:42:18.612Z",
"sequence": 18,
"correlation": {
"correlation_id": "corr_01K1CM8M6H3C8Y2F9S1T5B7Q4R",
"execution_id": "run_01K1CM8K2D9A6N3P7M5R1C8X0E",
"trace_id": "7f3a9d2c41b84e60a5ce927d1f0b3468",
"span_id": "18d49a7c2e5b310f"
},
"scope": {
"organization_ref": "orgref_synthetic_enterprise_01",
"environment": "production-eu",
"region": "eu-west",
"retention_class": "privileged-access-review",
"legal_hold": false
},
"actors": {
"requester": {
"id": "usr_service_desk_1842",
"type": "user",
"display_name": "Service desk analyst",
"identity_provider": "workforce-iam"
},
"delegated_user": {
"id": "usr_employee_74291",
"type": "user",
"display_name": "Synthetic employee",
"identity_provider": "workforce-iam"
},
"service_identity": {
"id": "svc_it_access_agent_prod",
"type": "service",
"identity_provider": "workload-identity"
},
"agent": {
"id": "agent_it_access",
"type": "agent",
"display_name": "IT access agent"
},
"accountable_owner": {
"id": "role_head_identity_operations",
"type": "organization",
"display_name": "Head of identity operations"
}
},
"components": {
"agent": {
"id": "it-access-agent",
"version": "release-2026.07.28.1",
"configuration_digest": "sha256:119375e6eac8b86aff5824d20f61c155af9e85d599a1750176424b27331846a4"
},
"model": {
"id": "support-routing-model",
"version": "2026-07-12",
"configuration_digest": "sha256:2278a23d62a7cfd1d2cb7146f2aa4f3544f80b4f4a244a9374351613b1257bab"
},
"prompt_template": {
"id": "it-access-system-instructions",
"version": "3.1.0",
"configuration_digest": "sha256:3f845cc216efadab4a56cc889571643042401a37b7ab889ee4f133a3a71803d7"
},
"orchestrator": {
"id": "it-service-request-process",
"version": "9",
"configuration_digest": "sha256:4fe8f53a00d40a83f68777532abeb95d5187cde4aa91dc51a2293d08787b54e2"
}
},
"requested_action": {
"action": "identity.group.grant_temporary_membership",
"purpose": "restore-approved-support-access",
"resource": {
"type": "directory_group",
"id": "grp_synthetic_support_admin"
},
"data_boundary_ref": "boundary_eu_identity_restricted",
"environment": "production-eu",
"requested_at": "2026-07-28T08:42:14.122Z"
},
"policy": {
"decision_id": "dec_01K1CM8P8F6S2B9Q1H7T3M5C0R",
"policy_id": "privileged-group-membership-policy",
"policy_version": "5.3.0",
"policy_digest": "sha256:54fc1465e4457217f909989f119ae46268619154501211421479176d201d278a",
"inputs_digest": "sha256:6bad7c722468ec1f1730f603453ad86505799c0b7a91ec2871c57f517d0eb594",
"decision": "require_approval",
"evaluated_at": "2026-07-28T08:42:14.188Z",
"matched_rule_ids": [
"privileged-group-requires-directory-admin"
],
"reason_codes": [
"privileged_access_requires_human_review"
]
},
"approval": {
"request_id": "dr_01K1CM8Q4N9K6T2D5B3M7X1S0E",
"status": "decided",
"requested_at": "2026-07-28T08:42:14.214Z",
"expires_at": "2026-07-28T09:12:14.214Z",
"required_role": "directory_administrator",
"presented_evidence_digest": "sha256:7244e8ef1ef619f46587e96705cb4224fb302548149acfb19a0e9fb4aeef6cc4",
"reviewer": {
"id": "usr_directory_admin_031",
"type": "user",
"display_name": "Directory administrator",
"identity_provider": "workforce-iam"
},
"decision": "approved",
"reason_code": "ticket_and_manager_authorization_verified",
"rationale_reference": "decision-note-tokenized-031",
"decided_at": "2026-07-28T08:42:17.902Z"
},
"tool_calls": [
{
"call_id": "call_01K1CM8R1E7P3M9C5Q2T6N8D0A",
"tool_id": "directory.group-membership",
"tool_version": "2026-07-20",
"action": "grant_temporary_membership",
"destination": "enterprise-directory-eu",
"requested_at": "2026-07-28T08:42:17.944Z",
"arguments_digest": "sha256:88af9aa314cf9fc2f4e5d2ba3dfd6b0ce8c1257d5e20fe322b41f244b21004f4",
"idempotency_key": "run_01K1CM8K2D9A6N3P7M5R1C8X0E:grant-membership",
"status": "succeeded",
"completed_at": "2026-07-28T08:42:18.433Z",
"result_digest": "sha256:9d711642b726b04401627ca9fbac32f5c8530fb1903cc4db02258717921a4881",
"downstream_effects": [
{
"system": "enterprise-directory-eu",
"effect_type": "temporary_group_membership_created",
"effect_reference": "effect_synthetic_91084",
"before_state_digest": "sha256:ac70c9a1c8fc8ec3d44de649f5d00a6c19352b965e8be9a757783cba06c8c131",
"after_state_digest": "sha256:b1cc2b32a36b12f15a0d6c6153b796f805c7064c07cb8a88e0f663e7085f8d2b"
}
]
}
],
"execution": {
"status": "succeeded",
"started_at": "2026-07-28T08:42:17.920Z",
"completed_at": "2026-07-28T08:42:18.481Z",
"business_outcome": {
"status": "achieved",
"summary": "The synthetic employee received time-bound support access after directory administrator approval.",
"reference": "outcome_synthetic_91084"
},
"rollback": {
"status": "not_required",
"reference": "scheduled-membership-expiry-20260728T124200Z"
}
},
"lineage": {
"lineage_record_id": "lin_01K1CM8R8A2C6N9Q3S5D7M1T0E",
"ordered_event_ids": [
"evt_request_01K1CM8M",
"evt_policy_01K1CM8P",
"evt_approval_01K1CM8Q",
"evt_tool_01K1CM8R",
"evt_01K1CM8R9K2Q7M1W3D5N6P8X0A"
]
},
"evidence": {
"manifest_ref": "bundle_manifest_synthetic_20260728_01",
"artifacts": [
{
"artifact_id": "artifact_policy_decision_01",
"artifact_type": "policy-decision",
"content_digest": "sha256:cd2eb0837c9b4c962c22d2ff8b5441b7b45805887dcc65d14f916888635af041"
},
{
"artifact_id": "artifact_directory_receipt_01",
"artifact_type": "tool-receipt",
"content_digest": "sha256:9d6f965ac832e40a5df6c06afe983e3b41e705464b706fef489a51e6d02eb9e9"
}
]
},
"privacy": {
"classification": "restricted",
"redaction_status": "tokenized",
"redactions": [
{
"json_pointer": "/audit_event/actors/delegated_user/id",
"method": "tokenized"
},
{
"json_pointer": "/audit_event/requested_action/resource/id",
"method": "tokenized"
}
],
"access_policy_ref": "evidence-access-identity-operations"
}
},
"integrity": {
"canonicalization": "RFC8785-JCS",
"hash_algorithm": "SHA-256",
"record_hash": "sha256:c0dd5a38d894b8da89af46c81eb5eac6271d568d43b02dbab60dc198996e5174",
"previous_event_hash": "sha256:d7862271e53b92a902e6eb57092e5dac27b8786a345c34894b4ab6408bc2aeed",
"signature": {
"algorithm": "Ed25519",
"key_id": "synthetic-example-key-2026-01",
"public_key_spki": "MCowBQYDK2VwAyEA5EaZT+JUGPhliobPiMPUDeW7CPyAtO7kUGob6TPdrqE=",
"value": "W6UD8vpV7oPkZt8rlzl9QcoelcYkwzv0bI9EgftZgVO0e5Us5TKfp55YE9K53xdhpThQi5Is7kAEJydQeRuhAA=="
},
"verification": {
"status": "not_performed",
"failure_codes": []
}
}
}Map the common audit object to the public schema
Use the schema groups as a portable normalization target. Preserve the original vendor record and its source identifier alongside the normalized event so an auditor can trace every field to its source.
| Common audit item | Schema field group | Evidence answer |
|---|---|---|
| Inventory and accountable owner | audit_event.scope; audit_event.actors.accountable_owner; audit_event.components.agent | Which agent ran, where, under whose responsibility, and under which retention class? |
| User, agent, service, and delegated identities | audit_event.actors | Which requester, delegated user, service identity, agent, and accountable owner participated? |
| Permissions, tools, and data boundaries | audit_event.requested_action; audit_event.policy; audit_event.tool_calls | Which resource, purpose, Data Boundary, policy input, tool, and destination governed authority? |
| Model, instructions, configuration, and Release | audit_event.components | Which agent, model, prompt template, orchestrator versions, and configuration digests executed? |
| Policy decisions and approval gates | audit_event.policy; audit_event.approval | Which policy outcome and human decision authorized or stopped the action? |
| Tool calls and downstream effects | audit_event.tool_calls[].downstream_effects | Which call reached which destination, and what state changed? |
| Human intervention, override, and escalation | audit_event.approval; linked ordered events and artifacts | Who intervened, with which role, evidence, reason, and time? |
| Execution lineage and business outcome | audit_event.execution; audit_event.lineage | What happened in order, and did the business outcome occur? |
| Incident, revocation, and rollback | audit_event.execution.rollback; linked lineage events and evidence artifacts | Which recovery path applied, and where is the incident or rollback evidence? |
| Retention, export, integrity, and verification | audit_event.scope; audit_event.evidence; audit_event.privacy; integrity | How is the record retained, handled, exported, chained, signed, and verified? |
Worked audit sample: Microsoft Copilot and a custom IT agent
Assume an employee asks a Microsoft 365 Copilot or a custom IT agent to restore access to a restricted support group. The table shows what each source can support and which evidence the enterprise must add.
| Audit stage | Microsoft Copilot evidence path | Custom-agent evidence path |
|---|---|---|
| Detection and request | Purview Copilot audit can identify the user interaction, time, application context, and referenced resources. Preserve the exact business request from retained interaction content or the source workflow. | requested_action and correlation identify the temporary membership request, purpose, resource, environment, and time. |
| Identity resolution | Copilot Studio Audit supplies user and agent identifiers where logged. Join Entra, agent sharing, connector credential, and delegation evidence. | actors resolves requester, delegated employee, service identity, agent, and accountable owner. |
| Permission check | Authentication and data-policy records show configured identity and connector boundaries. Join the directory authorization decision for the requested group. | policy records the policy and input digests, matched privileged-group rule, reason code, and require_approval outcome. |
| Policy and approval | Preserve the enterprise policy evaluation and human approval from the Process that holds the directory change. The reviewed Microsoft audit sources do not define one universal approval receipt for every Copilot action. | approval binds the Decision Request, evidence digest, directory-administrator role, reviewer, expiry, decision, reason, and decision time. |
| Execution and effect | Join any Copilot or plugin operation identifiers with the directory API receipt and before and after membership state. | tool_calls records the directory tool, arguments digest, idempotency key, result digest, and before and after state digests. |
| Evidence conclusion | State which interaction, transcript, configuration, identity, policy, approval, tool, and directory records were available. Qualify any missing source and preserve the exported originals. | lineage orders the events, execution records the business outcome, evidence lists artifacts, privacy records handling, and integrity states verification was not performed. |
How KLA implements platform-spanning audit
The KLA Control Plane governs instrumented agent actions on its own execution path. The KLA Policy Engine evaluates the proposed governed action and returns allow, warn, require_approval, or block. A require_approval outcome creates a Decision Request for Decision Desk, which records the human decision. Audit Trail and Lineage Explorer expose policy, approval, tool, and execution records for governed actions.
Evidence Room creates scoped Sealed Evidence Bundles from selected KLA records and supports integrity verification of the bundle manifest and proof material. These shipped capabilities apply to agents and tools instrumented through KLA’s governed path.
Ingesting and normalizing Microsoft Copilot or Salesforce Agentforce native audit exports into this evidence model is outside the shipped KLA scope today. An enterprise using those platforms still owns vendor export collection, source completeness, identity and configuration joins, downstream-effect reconciliation, retention decisions, chain of custody, and any adapter that maps vendor records into the public schema.
Primary sources and freshness
Source review completed 28 July 2026. Microsoft sources: Audit logs for Copilot and AI applications; Copilot Studio audit logs; Copilot Studio authentication; Copilot Studio data policies; Purview audit export; Purview audit retention policies; and Purview controls for Copilot Studio.
Additional Microsoft source: review Copilot Studio agent activity. Salesforce sources: Agentforce Session Tracing; Session Tracing setup; Session Tracing data model; Agentforce Session Trace OTel API; Agentforce DX metadata reference; common user access for agent actions; human review in Agentforce Operations; and Salesforce Setup Audit Trail.
KLA sources: the public AI Agent Audit Log Schema, the 12-domain enterprise audit framework, the human oversight guide, the AI agent access-control guide, and the AI agent IAM reference architecture.
Vendor capabilities vary by product, edition, license, region, channel, enabled service, tenant configuration, and release. Reconfirm the linked documentation and inspect the current tenant before relying on any collection path. This guide makes no universal access, retention, certification, or completeness claim.
Frequently Asked Questions
Does Microsoft Purview Audit capture enough for an AI agent audit on its own?
Purview supplies important Copilot interaction and administrative records. A complete enterprise audit also needs the accountable owner, effective identity and permissions, exact configuration, enterprise policy rationale, approval evidence, downstream receipts, incident links, and integrity evidence for the sampled action.
What is the difference between a Copilot audit log and a full evidence record?
A Copilot audit event records platform activity such as the user, time, application context, resource references, agent identifiers, or transcript reference. A full evidence record joins those facts with accountable ownership, delegated authority, configuration, policy, approval, downstream state, business outcome, retention, and verification.
What does Salesforce Agentforce log natively?
When Agentforce Session Tracing is enabled, Salesforce documents session, interaction, reasoning, action, prompt and gateway, error, response, metric, and feedback data in Data 360. Available fields and coverage depend on the enabled controls and the examined org.
Can Agentforce Session Tracing be exported to an external observability system?
Salesforce documents a beta OTel API for pulling one session at a time into an OTLP collector. Its current documentation limits retrieval to sessions started within the previous 72 hours, so the enterprise needs a collection design that accounts for that window.
Does Agentforce provide human approval for every agent action?
Salesforce documents human review for covered Agentforce Operations tasks. Other Agentforce actions may use Flow, custom actions, external systems, or business procedures. Audit the approval source that actually held and released the sampled action.
How do you audit a custom-built AI agent?
Instrument request, identity, permission, configuration, policy, approval, tool, downstream effect, outcome, incident, privacy, retention, and integrity records under stable correlation identifiers. Reconcile the event with source systems and verify the exported evidence independently.
Can one minimum-evidence checklist work across all three platforms?
Yes. Keep the ten audit questions fixed and vary the source records used to answer them. Mark unavailable evidence explicitly and qualify the conclusion when the platform or enterprise lacks a required source.
What should an auditor do when a vendor log omits a required field?
Collect an authoritative source from the identity provider, configuration system, policy service, approval workflow, downstream application, incident system, or evidence store. Preserve source provenance and record the gap when no equivalent evidence exists.
Does the custom-agent JSON example prove cryptographic integrity?
No. The example carries synthetic hash and signature-shaped values and records verification as not_performed. It demonstrates schema validity and explicit verification status. A real audit package requires genuine signing material and a completed independent verification.
Does KLA ingest Microsoft Copilot and Salesforce Agentforce audit exports today?
No. The shipped KLA scope governs its own instrumented execution path and creates records and evidence for that path. Vendor export collection and normalization remain enterprise responsibilities today.
Key Takeaways
One common audit method gives Microsoft Copilot, Salesforce Agentforce, and custom AI agents the same evidence questions. Collect the native records available in the examined tenant, add the missing identity, configuration, policy, approval, downstream, incident, and integrity evidence, then state the supported scope. Use the public AI Agent Audit Log Schema to normalize a sampled action and the Agent Audit Readiness Assessment to identify collection gaps.
