Skip to main content

Audit agent actions

Request and tool-call evidence at the Pomerium boundary

Enable MCP-specific authorization fields to record the caller, method, tool, parameters, request ID, and policy result for requests that pass through Pomerium.

What this pattern controls

MCP fields

Record the documented MCP method and tool fields.

Policy result

Record allow, deny, and policy reason fields.

Field control

Protect parameters and other sensitive log data.

Authorization record

Record the MCP call and policy result

Authorization logs describe the policy check. Configure only the fields that the organization needs and can protect.

  • Select mcp-method, mcp-tool, and mcp-tool-parameters when required.
  • Include the caller, request ID, allow or deny result, and policy reason.
  • Review sensitive fields before logging tool parameters or custom headers.

Logging boundary

Know what each Pomerium log can show

Keep authorization and proxy access logs separate. Pomerium records requests that pass through Pomerium.

  • Authorization logs describe the policy decision.
  • Proxy access logs describe incoming HTTP request and response fields.
  • Unproxied actions and an agent's internal reasoning are outside this boundary.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo