What teams usually need
- Per-agent identity attached to every action in the log stream
- Structured records for tools, APIs, files, and downstream systems
- Policy evaluation results stored with the event for later review
- Exports that compliance, security, and legal teams can actually use