Event types
Every event type written to ai_event_logs, its retention category, and which feed reads it.
- Type: reference
Every event type the gateway may write to ai_event_logs, and what each reader does with it.
Regenerate with make docs-generate.
Adding an event type means adding a row to the registry, classified. Readers derive their type sets from it rather than keeping their own allowlists — before CID-11 each reader kept one, so a new type was persisted correctly and displayed nowhere until somebody noticed.
By category
Retention is the shipped default window from RetentionPolicyService.SEED; an administrator can
change any window on Settings → Retention, and sweeping is off (enforced: false) until it is
switched on there. Nothing is deleted on an appliance where nobody enabled it.
| Category | Retention | Types |
|---|---|---|
AUDIT | 365 days | 19 |
ERROR | 90 days | 11 |
PERFORMANCE | 30 days | 2 |
REQUEST | 30 days | 5 |
SECURITY | 400 days | 35 |
All event types (72)
- Verdict / Kind present means rows of this type appear in the All Detections feed.
- Channel
derivedmeans the feed readsmetadata.tool, defaulting tobrowser. - Inspection is the effect shown on the inspection-ops admin page.
- Agent marks tool/agent telemetry — what a coding agent did, not a policy decision.
| Event type | Category | Retention | Verdict | Kind | Channel | Inspection | LLM review | Agent |
|---|---|---|---|---|---|---|---|---|
AI_USAGE | REQUEST | 30 days | — | — | — | — | — | — |
AUTH_FAILURE | SECURITY | 400 days | — | — | — | — | — | — |
AUTH_SUCCESS | SECURITY | 400 days | — | — | — | — | — | — |
CLAUDE_CODE_ACTIVITY | REQUEST | 30 days | — | — | — | — | — | prompt_or_tool_use |
CLAUDE_CODE_USAGE | REQUEST | 30 days | — | — | — | — | — | usage |
DIRECTORY_DEGRADED | SECURITY | 400 days | — | — | — | — | — | — |
DIRECTORY_LOGIN_UNAVAILABLE | SECURITY | 400 days | — | — | — | — | — | — |
DIRECTORY_RECOVERED | SECURITY | 400 days | — | — | — | — | — | — |
EXCEPTION | ERROR | 90 days | — | — | — | — | — | — |
FILE_INSPECTION_PARSE_FAILED | ERROR | 90 days | — | — | — | null | — | — |
FILE_UPLOAD_BLOCKED | SECURITY | 400 days | BLOCK | file | derived | block | — | — |
FILE_UPLOAD_REDACTED | SECURITY | 400 days | REDACT | file | derived | redact | — | — |
FILTER_BUNDLE_EXPORTED | AUDIT | 365 days | — | — | — | — | — | — |
GOVERNANCE_ASSET_DECOMMISSIONED | AUDIT | 365 days | — | — | — | — | — | — |
GOVERNANCE_ASSET_REGISTERED | AUDIT | 365 days | — | — | — | — | — | — |
GOVERNANCE_DRIFT_DETECTED | AUDIT | 365 days | — | — | — | — | — | — |
GOVERNANCE_POLICY_UPDATED | AUDIT | 365 days | — | — | — | — | — | — |
GUARDRAILS_DEGRADED | SECURITY | 400 days | — | — | — | — | — | — |
GUARDRAILS_FALLBACK | SECURITY | 400 days | — | — | — | — | — | — |
HAP_DETECTED | SECURITY | 400 days | — | — | — | — | — | — |
HELP_INPUT_FLAGGED | SECURITY | 400 days | FLAG | text | api | — | — | — |
HELP_INPUT_MASKED | SECURITY | 400 days | REDACT | text | api | — | — | — |
HELP_SETTINGS_UPDATED | AUDIT | 365 days | — | — | — | — | — | — |
IMAGE_ANALYSIS_DETECTION | SECURITY | 400 days | FLAG | image | api | — | — | — |
INSPECTION_ERROR | ERROR | 90 days | — | — | — | block | — | — |
INSPECTION_PARSE_FAILED | ERROR | 90 days | — | — | — | null | — | — |
INSPECTION_REDACTION_FAILED | ERROR | 90 days | — | — | — | block | — | — |
INSPECTION_TIMEOUT | ERROR | 90 days | — | — | — | block | — | — |
JAILBREAK_DETECTED | SECURITY | 400 days | — | — | — | — | — | — |
KNOWLEDGE_PROMOTED | AUDIT | 365 days | — | — | — | — | — | — |
LDAP_ADMIN_ROLE_DRIFT | SECURITY | 400 days | — | — | — | — | — | — |
LDAP_NAME_COLLISION | SECURITY | 400 days | — | — | — | — | — | — |
LICENSE_EXPIRED | SECURITY | 400 days | — | — | — | — | — | — |
LICENSE_EXPIRING | SECURITY | 400 days | — | — | — | — | — | — |
LICENSE_GRACE | SECURITY | 400 days | — | — | — | — | — | — |
LICENSE_LIMIT_EXCEEDED | SECURITY | 400 days | — | — | — | — | — | — |
LICENSE_TRIAL_EXPIRED | SECURITY | 400 days | — | — | — | — | — | — |
LLM_REVIEW_ANALYST_UNAVAILABLE | SECURITY | 400 days | — | — | — | — | critical | — |
LLM_REVIEW_COMPLETED | SECURITY | 400 days | — | — | — | — | info | — |
LLM_REVIEW_FAILED | ERROR | 90 days | — | — | — | — | warning | — |
LLM_REVIEW_TRIGGERED | SECURITY | 400 days | — | — | — | — | info | — |
MESSAGE_BLOCKED | SECURITY | 400 days | BLOCK | text | derived | block | — | — |
MESSAGE_MASKED | SECURITY | 400 days | REDACT | text | derived | redact | — | — |
OCR_SETTINGS_UPDATED | AUDIT | 365 days | — | — | — | — | — | — |
PASSWORD_RESET_COMPLETED | AUDIT | 365 days | — | — | — | — | — | — |
PASSWORD_RESET_DELIVERY | AUDIT | 365 days | — | — | — | — | — | — |
PASSWORD_RESET_LINK_ISSUED | AUDIT | 365 days | — | — | — | — | — | — |
PII_DETECTED | SECURITY | 400 days | FLAG | text | derived | allow | — | — |
POLICY_PROTECTION_CHANGED | SECURITY | 400 days | — | — | — | — | — | — |
PROVIDER_ERROR | ERROR | 90 days | — | — | — | — | — | — |
REQUEST_COMPLETE | REQUEST | 30 days | — | — | — | — | — | — |
REQUEST_START | REQUEST | 30 days | — | — | — | — | — | — |
RESOURCE_CREATED | AUDIT | 365 days | — | — | — | — | — | — |
RESOURCE_DELETED | AUDIT | 365 days | — | — | — | — | — | — |
RESOURCE_UPDATED | AUDIT | 365 days | — | — | — | — | — | — |
RESPONSE_INSPECTION_PARSE_FAILED | ERROR | 90 days | — | — | — | null | — | — |
RESPONSE_MASKED | SECURITY | 400 days | REDACT | text | derived | redact | — | — |
RESPONSE_PII_FLAGGED | SECURITY | 400 days | FLAG | text | derived | allow | — | — |
RISK_ANALYSIS_CANCELLED | AUDIT | 365 days | — | — | — | — | — | — |
RISK_ANALYSIS_COMPLETED | SECURITY | 400 days | — | — | — | — | — | — |
RISK_ANALYSIS_FAILED | ERROR | 90 days | — | — | — | — | — | — |
RISK_ANALYSIS_REQUESTED | AUDIT | 365 days | — | — | — | — | — | — |
SIEM_EXPORT_DEGRADED | SECURITY | 400 days | — | — | — | — | — | — |
SIEM_EXPORT_RECOVERED | SECURITY | 400 days | — | — | — | — | — | — |
SLOW_REQUEST | PERFORMANCE | 30 days | — | — | — | — | — | — |
TIMEOUT | PERFORMANCE | 30 days | — | — | — | — | — | — |
UNLOCK_DENIED | AUDIT | 365 days | — | — | — | — | info | — |
UNLOCK_REQUESTED | AUDIT | 365 days | — | — | — | — | warning | — |
USER_AI_LOCKED | SECURITY | 400 days | — | — | — | — | critical | — |
USER_AI_LOCKED_PENDING | SECURITY | 400 days | — | — | — | — | warning | — |
USER_AI_UNLOCKED | AUDIT | 365 days | — | — | — | — | info | — |
VALIDATION_ERROR | ERROR | 90 days | — | — | — | — | — | — |
Derived sets
| Set | Count | Types |
|---|---|---|
| Detections (All Detections feed) | 10 | MESSAGE_BLOCKED, MESSAGE_MASKED, PII_DETECTED, FILE_UPLOAD_BLOCKED, FILE_UPLOAD_REDACTED, RESPONSE_MASKED, RESPONSE_PII_FLAGGED, IMAGE_ANALYSIS_DETECTION, HELP_INPUT_MASKED, HELP_INPUT_FLAGGED |
| Managed-API channel | 3 | IMAGE_ANALYSIS_DETECTION, HELP_INPUT_MASKED, HELP_INPUT_FLAGGED |
| Inspection-ops admin | 13 | MESSAGE_BLOCKED, MESSAGE_MASKED, PII_DETECTED, FILE_UPLOAD_BLOCKED, FILE_UPLOAD_REDACTED, RESPONSE_MASKED, RESPONSE_PII_FLAGGED, INSPECTION_TIMEOUT, INSPECTION_ERROR, INSPECTION_REDACTION_FAILED, INSPECTION_PARSE_FAILED, FILE_INSPECTION_PARSE_FAILED, RESPONSE_INSPECTION_PARSE_FAILED |
| LLM Risk Analyst feed | 9 | LLM_REVIEW_TRIGGERED, LLM_REVIEW_COMPLETED, LLM_REVIEW_FAILED, USER_AI_LOCKED_PENDING, USER_AI_LOCKED, LLM_REVIEW_ANALYST_UNAVAILABLE, USER_AI_UNLOCKED, UNLOCK_REQUESTED, UNLOCK_DENIED |
| Agent activity (SIEM rollup) | 2 | CLAUDE_CODE_USAGE, CLAUDE_CODE_ACTIVITY |