Settings → Diagnostics
Diagnostics brings operational logs, audit trails, and task history together:
- Realtime — live stream of events from the API, Gateway, and Workers.
- App Logs — backend application log archive (server-side history with filters).
- API Logs — HTTP request audit trail with retention controls.
- Audit Logs — authentication, authorization, and access decisions.
- AI Audit — correlated agent, model, and tool execution activity.
- Tasks — local and Worker task execution history.
Realtime
Live streaming feed of every log line emitted by the API, Gateway, and the connected Workers. The stream starts live; use the Live / Paused toggle to freeze it while you read, and Clear to empty the buffer.
Filters
| Filter | Notes |
|---|---|
| Level | Debug, Info, Warning, Error, Critical (multi-select). |
| Source | The originating process or component (multi-select). |
Row anatomy
| Field | Notes |
|---|---|
| Timestamp | Shown in your local time. |
| Level | Color-coded badge. |
| Source | The originating process or component. |
| Logger | The specific logger within that source. |
| Message | Log message. |
| Extras | Structured key/value pairs attached to the log line. |
Permissions
- Read:
app.logs.read.
App Logs
Persisted backend application log archive. Same shape as the Realtime tab but historical — query by level, source, logger, time range, or full-text search.
Filters
| Filter | Notes |
|---|---|
| Level | Debug, Info, Warning, Error, Critical. |
| Source | The originating process or component. |
| Logger | Narrow to one logger within a source. |
| Date range | From / To timestamps. |
| Search | Free-text, via the search box on the table. |
Permissions
- Read:
app.logs.read.
API Logs
Audit trail of every HTTP request to the API. Use it to investigate “who did what when” and to clean up old entries when retention windows close.
Filters
| Filter | Notes |
|---|---|
| Action | The HTTP verb — GET, POST, PUT, PATCH, or DELETE. |
| Resource Type | The resource module the path targets. |
| User Email | Match a specific account. |
| Date range | From Date / To Date, applied with Apply Filters. |
Row anatomy
| Field | Notes |
|---|---|
| Date | Request timestamp. |
| Action | HTTP verb. |
| Path | The full URL path (without origin). |
| Resource ID | Captured from the URL when present. |
| User | Email of the authenticated caller, or Anonymous for unauthenticated. |
| Status | A Success (green) or Failed (red) badge. |
Click the eye button on a row (View Details) for the full request record.
Cleanup
A Cleanup Old Logs button at the top right purges entries older than the configured retention window. The retention value lives in Settings → System → Advanced Settings under api_log_retention_days.
Permissions
- Read:
app.logs.read. - Cleanup:
app.logs.delete.
Audit Logs
Security events record authentication, authorization, credential access, and
other security-relevant decisions. Filter them by event type, category,
severity, outcome, actor, or date range. Reading this tab requires
app.audit.read.
AI Audit
AI Audit answers “what did the AI do, who triggered it, and what happened?” It
groups a root agent execution with its model requests and tool calls through a
shared execution ID. External /mcp tool calls appear as their own roots with
available MCP client and API-key or OIDC attribution.
Row anatomy
| Field | Notes |
|---|---|
| Started / duration | When the activity ran and how long it took. |
| Activity | Agent execution, model call, or tool call and its origin. |
| Status | Running, success, failure, denied, timeout, cancelled, or unknown. |
| Actor | Triggering user, or SYSTEM for automation-playbook activity and every descendant. |
| Correlation | Session, execution, parent activity, MCP request, and external trace identifiers when available. |
| Target | Agent, configured/provider model, or tool. |
Filters
- Search, session ID, execution ID, activity ID, activity/event type, origin, status, severity, actor type, user, agent, model, tool, and date range.
Use cases
- Reconstruct an entire chat turn or background-agent execution.
- See the exact sequence of model and tool activity around a failure.
- Investigate which user or automation playbook caused a tool call.
- Correlate MisterShell calls made by an external agent platform.
Permissions
- Metadata:
app.ai.read. - Captured input/output content:
app.ai.write; content is fetched only after clicking Load content and the response is marked non-cacheable.
Inputs and outputs are stored as bounded, unredacted plaintext. Binary values
are replaced with type, size, and digest metadata. Platform owners are
responsible for encrypting database volumes, backups, and replicas and for
restricting direct database access. The default whole-row retention is seven
days (ai_audit_retention_days).
AI usage and budget accounting remain separate. Authorized operators can use Settings → AI → AI Usage, and every user can review their own token usage under Account → My AI Usage.
Tasks
Use the Worker / Local switch to inspect dispatched Worker tasks or server-side tasks such as AI chat and Quick Assist jobs. Filter by status, open task details, and cancel an active Worker task when authorized.