Skip to content
User Guide

Settings → Diagnostics

Diagnostics brings operational logs, audit trails, and task history together:

  • Realtime — live stream of events from the API, Gateway, and Workers.
  • App Logs — backend application log archive (server-side history with filters).
  • API Logs — HTTP request audit trail with retention controls.
  • Audit Logs — authentication, authorization, and access decisions.
  • AI Audit — correlated agent, model, and tool execution activity.
  • Tasks — local and Worker task execution history.

Realtime

Live streaming feed of every log line emitted by the API, Gateway, and the connected Workers. The stream starts live; use the Live / Paused toggle to freeze it while you read, and Clear to empty the buffer.

Filters

FilterNotes
LevelDebug, Info, Warning, Error, Critical (multi-select).
SourceThe originating process or component (multi-select).

Row anatomy

FieldNotes
TimestampShown in your local time.
LevelColor-coded badge.
SourceThe originating process or component.
LoggerThe specific logger within that source.
MessageLog message.
ExtrasStructured key/value pairs attached to the log line.

Permissions

  • Read: app.logs.read.

App Logs

Persisted backend application log archive. Same shape as the Realtime tab but historical — query by level, source, logger, time range, or full-text search.

Filters

FilterNotes
LevelDebug, Info, Warning, Error, Critical.
SourceThe originating process or component.
LoggerNarrow to one logger within a source.
Date rangeFrom / To timestamps.
SearchFree-text, via the search box on the table.

Permissions

  • Read: app.logs.read.

API Logs

Audit trail of every HTTP request to the API. Use it to investigate “who did what when” and to clean up old entries when retention windows close.

Filters

FilterNotes
ActionThe HTTP verb — GET, POST, PUT, PATCH, or DELETE.
Resource TypeThe resource module the path targets.
User EmailMatch a specific account.
Date rangeFrom Date / To Date, applied with Apply Filters.

Row anatomy

FieldNotes
DateRequest timestamp.
ActionHTTP verb.
PathThe full URL path (without origin).
Resource IDCaptured from the URL when present.
UserEmail of the authenticated caller, or Anonymous for unauthenticated.
StatusA Success (green) or Failed (red) badge.

Click the eye button on a row (View Details) for the full request record.

Cleanup

A Cleanup Old Logs button at the top right purges entries older than the configured retention window. The retention value lives in Settings → System → Advanced Settings under api_log_retention_days.

Permissions

  • Read: app.logs.read.
  • Cleanup: app.logs.delete.

Audit Logs

Security events record authentication, authorization, credential access, and other security-relevant decisions. Filter them by event type, category, severity, outcome, actor, or date range. Reading this tab requires app.audit.read.


AI Audit

AI Audit answers “what did the AI do, who triggered it, and what happened?” It groups a root agent execution with its model requests and tool calls through a shared execution ID. External /mcp tool calls appear as their own roots with available MCP client and API-key or OIDC attribution.

Row anatomy

FieldNotes
Started / durationWhen the activity ran and how long it took.
ActivityAgent execution, model call, or tool call and its origin.
StatusRunning, success, failure, denied, timeout, cancelled, or unknown.
ActorTriggering user, or SYSTEM for automation-playbook activity and every descendant.
CorrelationSession, execution, parent activity, MCP request, and external trace identifiers when available.
TargetAgent, configured/provider model, or tool.

Filters

  • Search, session ID, execution ID, activity ID, activity/event type, origin, status, severity, actor type, user, agent, model, tool, and date range.

Use cases

  • Reconstruct an entire chat turn or background-agent execution.
  • See the exact sequence of model and tool activity around a failure.
  • Investigate which user or automation playbook caused a tool call.
  • Correlate MisterShell calls made by an external agent platform.

Permissions

  • Metadata: app.ai.read.
  • Captured input/output content: app.ai.write; content is fetched only after clicking Load content and the response is marked non-cacheable.

Inputs and outputs are stored as bounded, unredacted plaintext. Binary values are replaced with type, size, and digest metadata. Platform owners are responsible for encrypting database volumes, backups, and replicas and for restricting direct database access. The default whole-row retention is seven days (ai_audit_retention_days).

AI usage and budget accounting remain separate. Authorized operators can use Settings → AI → AI Usage, and every user can review their own token usage under Account → My AI Usage.


Tasks

Use the Worker / Local switch to inspect dispatched Worker tasks or server-side tasks such as AI chat and Quick Assist jobs. Filter by status, open task details, and cancel an active Worker task when authorized.