Detection and the console read that one shape regardless of origin: one
chronological timeline instead of three tools with three logs.
Identity first
No event enters the store anonymous. Every ingest token is bound server-side to the account it was minted for, like a person’s CLI login, or a named external agent identity. See governance for accounts, tokens, and revocation.Surface: the agent runtime
Airlock controls this end to end.airlock claude
runs the agent in a network-isolated container whose only exit is the repo’s
egress proxy; your identity rides into both containers at start, so every
audit line is attributed at capture.
Two records come out of every session:
- Transcripts — prompts, replies, tool calls, and returned results: what the agent read and said.
- Egress events — every connection attempt, allowed or denied, with host, path, byte counts, and duration.
Surface: push ingestion
Agents that matter most often run outside any sandbox — resolution pipelines, triage bots, schedulers. They report through the same ingest API the CLI uses: an admin mints a named, scoped, revocable token per agent identity, and the agent POSTs its events — most importantly decision events, the conclusions systems act on, with evidence and confidence attached. Decision events are checked by the flagging rules in the same request that ingests them. The integration is one authenticated HTTP call; there is no SDK to adopt and no runtime to embed.Surface: SaaS audit connectors
Humans do not work inside a sandbox — their access is captured from the systems of record they already use. Audit connectors poll each platform’s admin/audit APIs on a schedule and write the same event shape:
Every connector declares its prerequisites up front. Required plan tier,
approval programs and realistic lead times, and credentials and scopes are all
stated before a connector enters a deployment plan.

