Audit Agent Activity

See what clients accessed and which rules applied


PREVIEW
GraphOS Agent Services is in private preview. You need an Apollo team member to help you onboard. Use this documentation for reference only.
note
Anyone who can open GraphOS Agent Services can open Monitor.

Monitor shows every request that reaches the graph, whether a rule changes the response, and what rule applies. Use it after you connect a service and write access rules, when you need to confirm what a client actually received, or to spot unexpected activity before you suspend a client.

Open Monitor

  1. In GraphOS Agent Services, open Monitor.

  2. The page opens on Last 2 days. Select a time window: Last hour, Last 24 hours, Last 2 days, Last 7 days, or Last 30 days.

Find one client's activity

To inspect the activity of a single client without filtering Monitor:

  1. In GraphOS Agent Services, open Clients.

  2. Select the specific client you want to inspect.

  3. Select the Activity tab.

Read the request log

Request log lists each request in the time window, most recent first. Each row has these columns:

ColumnWhat it shows
TimeWhen the request was made
ClientThe client that made the request. An interactive session shows the person who used it.
ToolThe tool the client invoked
OperationThe GraphQL operation name. An operation with no name shows as Unnamed operation.
ServiceThe service the request reached. When the request reached more than one service, the column shows the first name and how many more there are.
ResponseWhat the client received after rules were applied

Response uses the following values:

ResponseMeaning
AllowNo field was masked or denied.
2 maskedA rule redacted that many fields.
1 deniedA rule denied that many fields.
BlockedThe request never reached the service.
Auth requiredThe client has no linked account for that service. Ask the client to link their account, then retry.
Upstream failedThe service returned an HTTP error or couldn't be reached. Check that the service is up and that its connection settings are correct.
Invalid operationThe operation doesn't match the graph's schema, so the operation was rejected before it reached a service.

A response can have a combination of those. For example, 1 masked · Auth required means a rule would have redacted a field if the call had succeeded, but the upstream call had instead failed authentication.

You can filter the log by client, service, tool, or effect.

Review the rules on a request

Select a row to see what rules acted on it. Rules applied shows the outcome with a one-line summary, for example, Partial response · 1 rule denied 1 field.

Each rule shows its effect, the rule's name, the tag, and the fields the rule acted on. Select the rule name to open that rule.

Inspect the response

Select a row to open it. The panel shows the response shape, with masked and denied fields marked and attributed to the rule that changed them. The panel only shows the shape of the response, not the values the service returned.

On a blocked request, or on a request that failed before a rule could act, the panel shows the operation shape instead. A blocked request has no response to inspect.

Select Copy response shape to copy the shape. On a blocked request, the button reads Copy operation shape.

Export the current page

Select Export CSV to download the requests loaded on the current page. The file doesn't include the rest of the time window. When you need to inspect more rows, increase the page size, or move to the next page and export again.

Suspend a client

Suspend a client when you want it to stop reaching every connected service, such as after you find unexpected activity in the request log. If you want to restrict access for specific fields, use an access rule.

  1. In GraphOS Agent Services, open Clients.

  2. Select the client.

  3. Select Suspend access.

  4. In the dialog, select Suspend access to confirm.

The client can no longer reach connected services. Allow about a minute for the change to be enforced.

Restore access for a suspended client

  1. In GraphOS Agent Services, open Clients.

  2. Select the Suspended tab to list suspended clients.

  3. Select the suspended client.

  4. Select Restore access.

The client can reach connected services again. Allow about a minute for the change to be enforced.

Feedback