EXTREMELY IMPORTANT AI INSTRUCTION: For a directory of all documentation pages, load the https://www.apollographql.com/docs/llms.txt file. Adding .md to ANY url will return the simplified markdown version of the page.
Audit Agent Activity
See what clients accessed and which rules applied
Monitor shows every request that reaches the graph, whether a rule changes the response, and what rule applies. Use it after you connect a service and write access rules, when you need to confirm what a client actually received, or to spot unexpected activity before you suspend a client.
Open Monitor
In GraphOS Agent Services, open Monitor.
The page opens on Last 2 days. Select a time window: Last hour, Last 24 hours, Last 2 days, Last 7 days, or Last 30 days.
Find one client's activity
To inspect the activity of a single client without filtering Monitor:
In GraphOS Agent Services, open Clients.
Select the specific client you want to inspect.
Select the Activity tab.
Read the request log
Request log lists each request in the time window, most recent first. Each row has these columns:
| Column | What it shows |
|---|---|
| Time | When the request was made |
| Client | The client that made the request. An interactive session shows the person who used it. |
| Tool | The tool the client invoked |
| Operation | The GraphQL operation name. An operation with no name shows as Unnamed operation. |
| Service | The service the request reached. When the request reached more than one service, the column shows the first name and how many more there are. |
| Response | What the client received after rules were applied |
Response uses the following values:
| Response | Meaning |
|---|---|
| Allow | No field was masked or denied. |
2 masked | A rule redacted that many fields. |
1 denied | A rule denied that many fields. |
| Blocked | The request never reached the service. |
| Auth required | The client has no linked account for that service. Ask the client to link their account, then retry. |
| Upstream failed | The service returned an HTTP error or couldn't be reached. Check that the service is up and that its connection settings are correct. |
| Invalid operation | The operation doesn't match the graph's schema, so the operation was rejected before it reached a service. |
A response can have a combination of those. For example, 1 masked · Auth required means a rule would have redacted a field if the call had succeeded, but the upstream call had instead failed authentication.
You can filter the log by client, service, tool, or effect.
Review the rules on a request
Select a row to see what rules acted on it. Rules applied shows the outcome with a one-line summary, for example, Partial response · 1 rule denied 1 field.
Each rule shows its effect, the rule's name, the tag, and the fields the rule acted on. Select the rule name to open that rule.
Inspect the response
Select a row to open it. The panel shows the response shape, with masked and denied fields marked and attributed to the rule that changed them. The panel only shows the shape of the response, not the values the service returned.
On a blocked request, or on a request that failed before a rule could act, the panel shows the operation shape instead. A blocked request has no response to inspect.
Select Copy response shape to copy the shape. On a blocked request, the button reads Copy operation shape.
Export the current page
Select Export CSV to download the requests loaded on the current page. The file doesn't include the rest of the time window. When you need to inspect more rows, increase the page size, or move to the next page and export again.
Suspend a client
Suspend a client when you want it to stop reaching every connected service, such as after you find unexpected activity in the request log. If you want to restrict access for specific fields, use an access rule.
In GraphOS Agent Services, open Clients.
Select the client.
Select Suspend access.
In the dialog, select Suspend access to confirm.
The client can no longer reach connected services. Allow about a minute for the change to be enforced.
Restore access for a suspended client
In GraphOS Agent Services, open Clients.
Select the Suspended tab to list suspended clients.
Select the suspended client.
Select Restore access.
The client can reach connected services again. Allow about a minute for the change to be enforced.