Google AI:DEV 作者专属(RSS)· Auth By Example·· 3 小时前AI 评分31
工具调用日志不等于 AI 智能体审计轨迹
Tool traces are not an AI agent audit trail
AI 导读
LLM 可观测性日志只能显示提示词、工具名和延迟,不足以支撑审计。审计需要的是执行边界上的授权信封:智能体身份与人类主体或委托链、工具+资源+动作、策略 ID/版本及允许或拒绝理由、策略要求时的 HITL 审批,以及把决策与副作用关联起来的关联 ID。仅在工具运行后记录日志会错过控制点,应优先采用在执行前做出决策的 PDP 或 MCP 网关。
正文
An LLM observability log can show the prompt, the tool name, and the latency. Useful for debugging. Not enough for an auditor.
When someone asks "what did this agent do, and why was it allowed?", you need an authorization envelope at the enforcement boundary:
- Agent identity plus the human principal or delegation chain
- Tool + resource + action
- Policy ID/version and allow/deny with a reason
- HITL approval when the policy required one
- Correlation IDs that join the decision to the side effect
Logging only after the tool runs misses the control point. Prefer the PDP or MCP gateway that decides before execution.
I work at Permit.io — we wrote up the minimum evidence package for an AI agent audit trail:
来源:Google AI:DEV 作者专属(RSS) · dev.to