Glossary · Records and compliance
Audit trail (agent exchanges)
A chronological record that lets you reconstruct what two agents asked, answered and did in an exchange, who was involved, and how it ended.
An audit trail for agent exchanges is a chronological record, kept by each party, that is complete enough to reconstruct what the agents asked, answered and did, who was involved, and what the outcome was.
Definition. NIST’s glossary describes an audit trail as a chronological record that lets someone reconstruct and examine the sequence of events surrounding a security-relevant transaction, from inception to result. For agents, the transaction is usually one A2A task, or a conversation that spans several tasks.
What to record. NIST SP 800-53 control AU-3 asks that each audit record establish what happened, when, where, the source, the outcome, and the identity of those involved. In an A2A exchange that maps onto:
| AU-3 element | A2A source |
|---|---|
| What | The operation (SendMessage, CancelTask), each task state change, and the artifacts produced |
| When | Status timestamp values and the server’s own receive time |
| Where | The endpoint and binding that handled the request |
| Source | The authenticated client identity from the request’s security scheme |
| Outcome | The final TASK_STATE_* value or the error code |
| Identity | Task id, contextId, each messageId, and the agent or person the client acts for |
The A2A enterprise guide recommends logging task IDs, correlation IDs and trace context, and auditing task creation, critical state changes and agent actions. Illustrative log entry:
{"loggedAt": "2026-09-26T14:03:12.004Z", "event": "task.status_changed", "taskId": "5f1c2d9e-8b7a-4e3c-9d21-6a0b4c7e2f13", "contextId": "ctx-7", "messageId": "3b8f0c2e-5d1a-4f6b-9e7c-2a4d6f8b0c1e", "client": "partner-agent-17", "state": "TASK_STATE_COMPLETED"}
Keep your own copy. A2A section 3.7 says an agent decides which messages to keep in task history and may drop some. A client cannot rely on GetTask to reconstruct an exchange later, so each side needs its own trail.
Protecting it. AU-9 calls for protecting audit information from unauthorized access, modification and deletion, and its enhancement AU-9(3) uses cryptography to protect integrity. AU-11 covers retention for later investigations and regulatory requirements. When both sides must agree on what happened, a signed receipt goes further than two separate logs.
Neighbouring terms. A receipt is a signed record of one exchange that both sides can hold.
Sources
- NIST CSRC Glossary: audit trail (accessed )
- NIST SP 800-53 Rev. 5 control catalog (AU-3, AU-9, AU-10, AU-11), OSCAL JSON (accessed )
- A2A documentation: Enterprise Implementation of A2A (tracing, logging and auditing) (accessed )
- A2A Protocol Specification, section 3.7: Messages and Artifacts (accessed )