What to trace

Trace the moment an agent requests a tool call. Include the agent identity, environment, tool name, constrained arguments, destination, policy version and final verdict.

That gives teams visibility into both successful work and blocked attempts.

What telemetry reveals

Authorization telemetry shows where agents are accumulating privileges, which tools trigger exceptions and which policies create friction. It also helps distinguish a malicious attempt from a workflow that needs a narrower approved path.

The value comes from decision context, not event volume.

How to operate it

Export metrics and traces into existing observability tools, but keep the enforcement decision deterministic and local. Telemetry should explain what happened; it should not be the only thing preventing action.

Policy before action. Evidence after execution.