| Skipped Actions | What was considered but not done | Recommended |
| Confidence Levels | Certainty of responses given | Recommended |
3. Log Entry Structure
Every log entry must contain:
{
"timestamp": "ISO-8601 format",
"session_id": "unique session identifier",
"turn_number": 3,
"action_type": "tool_call | response | decision | error",
"description": "Human-readable summary",
"input": "What triggered this action",
"output": "Result of the action",
"confidence": 0.92,
"reasoning": "Why this action was chosen",
"alternatives_considered": ["option_a", "option_b"],
"duration_ms": 145
}
4. Decision Trace Format
For every non-trivial decision, record:
- Context — What information was available
- Options — What alternatives existed
- Selection — Which option was chosen
- Rationale — Why this option was best
- Confidence — How certain the decision was
- Fallback — What to do if the decision proves wrong
5. Logging Levels
| Level | When to Use | Retention |
| DEBUG | Internal processing details | 24 hours |
| INFO | Normal operations, decisions | 30 days |
| WARN | Unexpected but handled situations | 90 days |
| ERROR | Failures requiring attention | 1 year |
| CRITICAL | System-level failures, data issues | Permanent |
6. Privacy in Logging
Never log:
- Passwords, tokens, or API keys
- Full credit card or SSN numbers
- Raw personal health information
- Private messages not relevant to the task
Always redact:
- Email addresses →
u***@domain.com
- Phone numbers →
--1234
- Names in sensitive contexts →
[USER]
7. Audit Trail Requirements
For actions that modify data or have external effects:
| Field | Description |
| Before State | System state before action |
| Action Performed | Exact operation executed |
| After State | System state after action |
| Reversibility | Can this be undone? How? |
| Authorization | What permission allowed this |
8. Common Logging Mistakes
| Mistake | Why It's a Problem | Correct Approach |
| Logging too little | Cannot debug failures | Log all decisions and actions |
| Logging too much | Performance impact, noise | Use appropriate log levels |
| Unstructured logs | Cannot parse or search | Use consistent JSON format |
| Missing timestamps | Cannot reconstruct sequence | Always include ISO-8601 |
| Logging sensitive data | Privacy violation | Redact before logging |
9. Using Logs for Improvement
- Analyze error patterns to identify common failure modes
- Track decision confidence over time to measure improvement
- Identify frequently escalated topics for knowledge base updates
- Monitor response times to detect performance degradation
- Review low-confidence decisions for training opportunities
10. Error Cases
| Scenario | Response |
| Logging system unavailable | Continue operating, buffer logs in memory, flush when available |
| Log storage full | Alert system administrator, continue with reduced logging |