Dd Audit Ai Activity

作者 datadog-labs5b40c73824ec无许可证177 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Audit what the Bits AI assistant (MCP server) has done in your Datadog org — tool calls by user, resources accessed, and anomaly flags for AI governance.

AI 生成的概览

通过 Audit Trail 审计 Datadog Bits AI 的 MCP 工具活动,展示用户、操作、资源与异常标记。

功能
该技能提供一组 Datadog Audit Trail 查询,用于呈现 Bits AI 助手(MCP 服务器)在组织内做过什么。它会报告按用户划分的工具调用、执行的操作、受影响的资源类型与 ID、客户端 IP 与国家,并生成包含总量、活跃用户、操作分布和资源类型的每周汇总。它还会列出异常信号,例如破坏性 AI 操作、支持用户活动、首次使用的用户、高频调用以及超出范围的资源访问,并定义了审计报告的文本输出格式。
适用场景
适用于对 AI 操作进行安全审查、需要 AI 活动可记录且可归属到具体用户的合规审计,以及关于 AI 助手采用情况与风险面的治理报告。当你需要了解哪些用户调用了 Datadog AI 助手以及它改动了什么时,适合使用。
运行要求
需要可访问 Datadog 的 pup CLI,通过 pup auth login(OAuth2)或具备 audit_logs_read 权限的 DD_API_KEY 与 DD_APP_KEY 进行认证,并使用 jq 处理 JSON 管道。需要访问 Datadog Audit Trail 的网络连接。该技能不附带脚本,仅为说明与 shell 查询。

Audit Trail: AI Activity Audit

Every Datadog MCP tool call is recorded in Audit Trail under the Bits AI SRE category. This skill surfaces what the AI assistant has done in your org — which users invoked it, which tools were called, and which resources were affected.

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Queries

All MCP tool activity in a time window

bash
pup audit-logs search --query "@evt.name:\"MCP Server\"" --from 7d --limit 500 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      actor_type: .attributes.attributes.evt.actor.type,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Activity by user (who is using the AI assistant most?)

bash
pup audit-logs search --query "@evt.name:\"MCP Server\"" --from 30d --limit 1000 -o json \  | jq '[.data[] | .attributes.attributes.usr.email]    | group_by(.)    | map({user: .[0], tool_calls: length})    | sort_by(-.tool_calls)'

Resources modified by AI tool calls

bash
pup audit-logs search \  --query "@evt.name:\"MCP Server\" @action:(created OR modified OR deleted)" \  --from 7d --limit 500 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id    }]'

AI activity for a specific user

bash
pup audit-logs search \  --query "@evt.name:\"MCP Server\" @usr.email:[email protected]" \  --from 30d --limit 500 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id    }]'

Weekly summary report

bash
pup audit-logs search --query "@evt.name:\"MCP Server\"" --from 7d --limit 1000 -o json \  | jq '{      total_tool_calls: (.data | length),      unique_users: ([.data[] | .attributes.attributes.usr.email] | unique | length),      top_users: (        [.data[] | .attributes.attributes.usr.email]        | group_by(.)        | map({user: .[0], calls: length})        | sort_by(-.calls)        | .[:5]      ),      actions_breakdown: (        [.data[] | .attributes.attributes.action]        | group_by(.)        | map({action: .[0], count: length})        | sort_by(-.count)      ),      resource_types: (        [.data[] | .attributes.attributes.asset.type]        | group_by(.)        | map({type: .[0], count: length})        | sort_by(-.count)      )    }'

Anomaly Flags

SignalGovernance concern
AI performing deleted actions on monitors or dashboardsReview whether destructive AI operations are expected
AI acting as SUPPORT_USERDatadog support using AI on behalf of org
First-time user invoking AI toolsNew user accessing AI assistant
High volume of tool calls in short windowAutomated/batch AI usage
AI accessing resources outside user's normal scopePotential over-permissioned AI session

Output Format

AI Activity Audit — [Org] — [Date Range]
Total MCP tool calls: [N]Unique users: [N]
Top users:  [[email protected]]: [N] calls
Actions breakdown:  accessed: [N]  modified: [N]  created: [N]  deleted: [N]
Resource types affected:  dashboard: [N]  monitor: [N]
Anomalies:  [List any flagged events with timestamp, user, action, resource]

Context

This skill is most useful for:

  • Security reviews: Verifying AI actions were authorized and within expected scope
  • Compliance audits: Demonstrating AI activity is logged and attributable to specific users
  • Governance reports: Understanding adoption and risk surface of the AI assistant across the org

No other observability vendor audits their AI assistant's actions at this level of detail.

References

来源与署名

来源:datadog-labs/agent-skills位于dd-audit/ai-activity-audit提交5b40c73

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架