Skip to main content

๐Ÿ›ก๏ธ Audit Policy

๐Ÿ‘ค Who it's for: Security Administrators / Compliance Officers
โฑ๏ธ Read time: ~5 minutes
๐Ÿ’ก In one line: Who did what and when โ€” everything is traceable.

YingClaw has a built-in operation auditing system that records all critical actions with flexible policy configuration for enterprise security auditing and compliance.

Featuresโ€‹

FeatureDescription
๐Ÿ” Operation AuditRecord user actions, system events, tool invocations, and more
โš™๏ธ Policy ConfigurationCustom audit rules with flexible scope and alert conditions
๐Ÿ“Š Audit StatusReal-time view of audit system status and toggle
๐Ÿ“‹ Compliance ReportsExportable audit logs for regulatory and internal reviews

Audit Event Typesโ€‹

YingClaw's audit system covers the following event types:

Event TypeDescription
User Login/LogoutRecords all login attempts and results
Agent Start/EndTracks AI Agent creation and destruction
Tool InvocationRecords shell commands, file operations, network requests
Config ChangesTracks all configuration file modifications
Channel MessagesRecords messages sent and received across platforms

How to Useโ€‹

View Audit Statusโ€‹

Log into the YingClaw Web Console and click "Audit Policy" in the left navigation.

On the "Status" tab you can view:

  • Whether the audit system is enabled
  • Current audit event statistics
  • System health status

Configure Audit Policyโ€‹

Switch to the "Policy" tab to customize:

  • Audit toggle (global enable/disable)
  • Event filtering rules (select which event types to record)
  • Alert threshold configuration

Audit Logsโ€‹

Each audit event record contains:

  • Timestamp
  • Actor identity
  • Action type
  • Action details
  • Result

Notesโ€‹

  • โš ๏ธ A disclaimer must be accepted on first visit to the audit page
  • ๐Ÿ” Audit policy configuration requires administrator privileges
  • ๐Ÿ“ Audit logs consume storage โ€” schedule regular archiving

Next Stepsโ€‹

Learn about ๐Ÿ”„ Updates to keep your system current.